Zakra <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta REST API (CVE-2026-4804) | HOL Guard CVE