CubeWP Framework <= 1.1.30 - Unauthenticated Arbitrary File Read via prev_icon/next_icon Parameter (CVE-2026-13339) | HOL Guard CVE