Medium 6.4 2025-06-26< 2.3.7 WordPress Image Editor by Pixo Plugin <= 2.3.6 is vulnerable to Cross Site Scripting (XSS) EUVDPatchstackWordfenceCVE