Charitable <= 1.8.12.1 - Authenticated (Contributor+) SQL Injection via 'order' Shortcode Attribute (CVE-2026-77189) | HOL Guard CVE