WPCafe <= 3.0.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via REST API (CVE-2026-11818) | HOL Guard CVE