Vulnerability Description
The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins load a JavaScript file which has been compromised from an apparent abandoned S3 bucket. It can be used as a backdoor by those who control it, but it currently displays an alert marketing security services. Users that pay are added to allowedDomains to suppress the popup.
CVSS Score
CRITICAL
References
- https://wpscan.com/vulnerability/a0c70b98-a3f9-4d4c-a25f-81424230b1a5/
- https://wpscan.com/vulnerability/a0c70b98-a3f9-4d4c-a25f-81424230b1a5/
FAQ
What is CVE-2025-8047?
CVE-2025-8047 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins load a JavaScript file which has been compromised from an apparent abandoned S3...
How severe is CVE-2025-8047?
CVE-2025-8047 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-8047?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.