The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins load a JavaScript file which has been compromised from an apparent abandoned S3 bucket. It can be used as a backdoor by those who control it, but it currently displays an alert marketing security services. Users that pay are added to allowedDomains to suppress the popup.
Metrics
Affected Vendors & Products
References
History
Thu, 14 Aug 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 14 Aug 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wordpress
Wordpress wordpress |
|
Vendors & Products |
Wordpress
Wordpress wordpress |
Thu, 14 Aug 2025 10:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins load a JavaScript file which has been compromised from an apparent abandoned S3 bucket. It can be used as a backdoor by those who control it, but it currently displays an alert marketing security services. Users that pay are added to allowedDomains to suppress the popup. | |
Title | Multiple Plugins from itayamar - Supply Chain Compromise | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-08-14T09:53:17.108Z
Updated: 2025-08-14T14:49:11.501Z
Reserved: 2025-07-22T12:37:49.835Z
Link: CVE-2025-8047

Updated: 2025-08-14T13:36:29.142Z

Status : Awaiting Analysis
Published: 2025-08-14T10:15:29.510
Modified: 2025-08-14T15:15:42.840
Link: CVE-2025-8047

No data.