WPML Multilingual CMS <= 4.9.5 - Authenticated (Translator+) SQL Injection via 'sorting' Parameter (CVE-2026-12248) | HOL Guard CVE