WordPress Creative Mail plugin <= 1.6.9 - SQL Injection vulnerability (CVE-2026-65547) | HOL Guard CVE