GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form (CVE-2026-13704) | HOL Guard CVE