9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins load a JavaScript file which has been compromised from an apparent abandoned S3 bucket. It can be used as a backdoor by those who control it, but it currently displays an alert marketing security services. Users that pay are added to allowedDomains to suppress the popup.
Basic Information
ID
CVE-2025-8047
Source
WPScan
Published
Aug 14, 2025 at 09:53
Modified
Aug 14, 2025 at 14:49
Affected Product
Vendor
Unknown
Product
disable-right-click-powered-by-pixterme
Affected Versions
Unknown disable-right-click-powered-by-pixterme 0
Unknown pixter-image-digital-license 0
Unknown pixter-image-digital-license 0