WordPress Loops & Logic plugin <= 4.2.3 - Cross Site Scripting (XSS) vulnerability (CVE-2026-57391) | HOL Guard CVE