WordPress Simply Schedule Appointments plugin <= 1.6.12.29 - Broken Access Control vulnerability (CVE-2026-94074) | HOL Guard CVE