XenForo < 2.3.13 OAuth2 Authorization Code Token Theft via redirect_uri Bypass (CVE-2026-73310) | HOL Guard CVE