WPCafe < 3.0.18 - Unauthenticated Reservation Approval Bypass via Missing Authorization (CVE-2026-14550) | HOL Guard CVE