PopCash Code Integration Tool
PopCash Code Integration Tool has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2017 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 5.7, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Missing Authorization.
Every one of the 2 issues recorded for PopCash Code Integration Tool has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. PopCash Code Integration Tool is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2017-15810PopCash Code Integration Tool < 1.1 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

PopCash Code Integration Tool
Author
PopCash
The plugin offers WordPress publishers the possibility to integrate the PopCash.Net pop-under code by two methods: either through inserting User ID (UID) and Website ID (WID) or through copying and pasting the code obtained through your PopCash.Net user panel. More than this, the plugin also offers users the option to temporarily disable the code integration without having to uninstall or deactivate the plugin
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C