WordPress Headless Single Sign On plugin <= 1.7.0 - Broken Authentication vulnerability (CVE-2026-62108) | HOL Guard CVE