Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'caption' Parameter (CVE-2026-6172) | HOL Guard CVE