WordPress Simply Schedule Appointments plugin <= 1.6.12.4 - Broken Access Control vulnerability (CVE-2026-57812) | HOL Guard CVE