Security release. Per-post capability checks on the bulk FAQ and Elementor routes, shared validation for bulk FAQ writes (including the empty/"0"/failed-delete edge cases), and the info endpoint now requires edit_posts. No behaviour change for authorized callers. See #3.