N/A Unfixed Closed 2026-03-20≤ 0.3 Vagaro Booking Widget <= 0.3 - Unauthenticated Stored Cross-Site Scripting via 'vagaro_code' WordfenceCVE