WC Vendors <= 2.7.0 - Authenticated (Shop Manager+) SQL Injection via 'status' Parameter (CVE-2026-15351) | HOL Guard CVE