WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter (CVE-2026-15094) | HOL Guard CVE