Custom Field Template <= 2.7.8 - Authenticated (Contributor+) SQL Injection via 'post_ID' Parameter (CVE-2026-9855) | HOL Guard CVE