WP Inventory Manager <= 2.5.1 - Authenticated (Contributor+) SQL Injection via 'where' Shortcode Attribute (CVE-2026-17607) | HOL Guard CVE