WP User Frontend < 4.3.11 - Subscriber+ PHP Object Injection via Frontend Post Edit Form (CVE-2026-19116) | HOL Guard CVE