WP Directory Kit < 1.5.6 - Subscriber+ SQL Injection via section Parameter (CVE-2026-18230) | HOL Guard CVE