WordPress Stripe Payments plugin <= 2.1.2 - Cross Site Scripting (XSS) vulnerability (CVE-2026-78282) | HOL Guard CVE