WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.0.0 - Broken Authentication vulnerability (CVE-2026-28008) | HOL Guard CVE