WordPress Templately plugin <= 3.7.1 - Cross Site Scripting (XSS) vulnerability (CVE-2026-66667) | HOL Guard CVE