WordPress SmartSMTP plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability (CVE-2026-66606) | HOL Guard CVE