AR for WordPress <= 8.40 - Unauthenticated Arbitrary File Read via 'file' Parameter (CVE-2026-14327) | HOL Guard CVE