Smart Custom Fields <= 5.0.7 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title (CVE-2026-2594) | HOL Guard CVE