Multiple Plugins by itayamar - Backdoored Software

2025-07-23 00:00
Mike Gozdiskowski

Strategic Overview

Status
Unpatched
Affected Version<= 1.0
CVSS9.8Critical
CVECVE-2025-8047
View all Image License and Protection vulnerabilities

Vulnerability Overview

Multiple plugins by itayamar for WordPress have been compromised via a supply chain attack. This is due to an abandoned S3 bucket getting compromised and delivering malware through https://pixter-loader-assets.s3.amazonaws.com/Loader/v3Loader.js. This makes it possible for unauthenticated attackers to obtained backdoored access.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-829 (Inclusion of Functionality from Untrusted Control Sphere) The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C