WP Directory Kit < 1.5.5 - Unauthenticated SQL Injection via 'field_search' Parameter (CVE-2026-18473) | HOL Guard CVE