wpForo Forum <= 2.4.17 - Unauthenticated SQL Injection via 'referer' Parameter (CVE-2026-5097) | HOL Guard CVE