WordPress AfterShip Tracking plugin <= 1.18.1 - Cross Site Scripting (XSS) vulnerability (CVE-2026-66460) | HOL Guard CVE