WordPress Simply Schedule Appointments plugin <= 1.6.11.11 - Broken Access Control vulnerability (CVE-2026-59523) | HOL Guard CVE