Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta (CVE-2026-16273) | HOL Guard CVE