Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Author+) Bulk Appointment Manipulation (CVE-2026-11992) | HOL Guard CVE