Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors <= 4.15.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'profile_fields_user_email_value_prefix' Parameter (CVE-2026-85657) | HOL Guard CVE