Medium 4.4 Unfixed 2026-02-14≤ 2.5 Link Hopper <= 2.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'hop_name' Parameter CVEWordfence