WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19.1 - PHP Object Injection vulnerability (CVE-2026-94677) | HOL Guard CVE