WordPress Simply Schedule Appointments plugin <= 1.6.12.31 - Insecure Direct Object References (IDOR) vulnerability (CVE-2026-94673) | HOL Guard CVE