CVE-2026-24600 | PenciDesign Penci Review Plugin up to 3.5 on WordPress cross site scripting
A vulnerability labeled as problematic has been found in PenciDesign Penci Review Plugin up to 3.5 on WordPress. Impacted is an unknown function. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2026-24600. The attack may be performed from remote. There is no available exploit.