WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title (CVE-2026-14292) | HOL Guard CVE