ConvertPlus <= 3.6.3 - Authenticated (Subscriber+) PHP Object Injection via 'style' Parameter (CVE-2026-87741) | HOL Guard CVE