WordPress FluentCRM Pro plugin <= 3.1.12 - Server Side Request Forgery (SSRF) vulnerability (CVE-2026-78277) | HOL Guard CVE