WordPress FundEngine plugin <= 1.7.6 - Broken Access Control vulnerability (CVE-2026-57406) | HOL Guard CVE