Medium 5.9 Unfixed 2025-12-24≤ 2.0.2 WordPress Gift Hunt plugin <= 2.0.2 - Cross Site Scripting (XSS) vulnerability CVEWordfence