ShopEngine < 4.9.3 - Customer PII Disclosure via Forced Authentication (CVE-2026-19088) | HOL Guard CVE