PopCash Code Integration Tool

PopCash Code Integration Tool has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2017 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 5.7, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 2 issues recorded for PopCash Code Integration Tool has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. PopCash Code Integration Tool is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
5.7/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all PopCash Code Integration Tool vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2017-15810

PopCash Code Integration Tool < 1.1 - Reflected Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
PopCash Code Integration Tool banner
Latestv2.0

PopCash Code Integration Tool

PopCash

Author

PopCash

4.0(8)
80/100
Last Updated
2026-03-16 (6mo ago)
Active Installs
300+
Downloads
39,924
Requires WP
5.0+
Requires PHP
7.0+
Tested up to
WP 6.9.7
Created
2016-07-04 (10y ago)

The plugin offers WordPress publishers the possibility to integrate the PopCash.Net pop-under code by two methods: either through inserting User ID (UID) and Website ID (WID) or through copying and pasting the code obtained through your PopCash.Net user panel. More than this, the plugin also offers users the option to temporarily disable the code integration without having to uninstall or deactivate the plugin

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C