Advanced Popups <= 1.2.3 - Authenticated (Author+) Stored Cross-Site Scripting via 'Notification Button Link' Field (CVE-2026-11996) | HOL Guard CVE