WP OAuth Server < 6.3.1 - Unauthenticated OAuth Token and User Data Disclosure via Debug Log File (CVE-2026-19715) | HOL Guard CVE