WordPress Simple Payment plugin <= 2.5.1 - Cross Site Scripting (XSS) vulnerability (CVE-2026-81292) | HOL Guard CVE