WordPress Quick Event Manager plugin <= 9.17 - Cross Site Scripting (XSS) vulnerability (CVE-2026-84848) | HOL Guard CVE