phpMyFAQ enables unauthenticated 2FA brute-force attack via /admin/check acceptance of arbitrary user-id (CVE-2026-45010) | HOL Guard CVE