Multiple Plugins by itayamar - Backdoored Software
Strategic Overview
<= 1.0CVE-2025-8047Vulnerability Overview
Multiple plugins by itayamar for WordPress have been compromised via a supply chain attack. This is due to an abandoned S3 bucket getting compromised and delivering malware through https://pixter-loader-assets.s3.amazonaws.com/Loader/v3Loader.js. This makes it possible for unauthenticated attackers to obtained backdoored access.
Technical Analysis
REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-829 (Inclusion of Functionality from Untrusted Control Sphere) The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C