Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript (CVE-2026-55596) | HOL Guard CVE