ShareOpenly has Cross-Site Scripting (XSS) via Missing esc_url() on Shared URL in Content Output (CVE-2026-48094) | HOL Guard CVE