CVE-2025-8047: Unknown Disable-Right-Click-Powered-By-Pixterme

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins load a JavaScript file which has been compromised from an apparent abandoned S3 bucket. It can be used as a backdoor by those who control it, but it currently displays an alert marketing security services. Users that pay are added to allowedDomains to suppress the popup.

Affected products

  • Unknown Disable-Right-Click-Powered-By-Pixterme: up to and including 1.2
  • Unknown Pixter-Image-Digital-License: up to and including 1.0

Published 2025-08-14. Last modified 2026-06-17.