MotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection via 's' Parameter (CVE-2026-13454) | HOL Guard CVE