WCPOS <= 1.9.14 - Authenticated (Shop Manager+) Code Injection via 'thermal' Template Engine (CVE-2026-17581) | HOL Guard CVE