A vulnerability was found in PopAd Plugin up to 1.0.4 on WordPress. It has been declared as problematic. The affected element is the function PopAd_reset_cookie_time of the component Setting Handler. The manipulation results in cross-site request forgery.

This vulnerability is reported as CVE-2025-9616. The attack can be launched remotely. No exploit exists.