WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - Cross Site Scripting (XSS) vulnerability (CVE-2026-65513) | HOL Guard CVE