WordPress Tagembed plugin <= 7.4 - Cross Site Scripting (XSS) vulnerability (CVE-2026-66590) | HOL Guard CVE