WP Directory Kit < 1.5.7 - Admin+ SQL Injection via section Parameter (CVE-2026-18653) | HOL Guard CVE