WordPress Simple Payment plugin <= 2.5.4 - Cross Site Scripting (XSS) vulnerability (CVE-2026-62111) | HOL Guard CVE