CVE-2024-10938
Received Received - Intake
Malicious .htaccess Files in OVRI Payment Plugin

Publication date: 2026-02-27

Last updated on: 2026-02-27

Assigner: Wordfence

Description
The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives to prevent the execution of certain scripts while allowing execution of known malicious PHP files. If moved outside of the plugin's directory, they may interfere with the proper function of a site.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-02-27
Last Modified
2026-02-27
Generated
2026-06-16
AI Q&A
2026-02-27
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
ovri payment_plugin 1.7.0
moneytigo ovri_payment_plugin 1.7.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-506 The product contains code that appears to be malicious in nature.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Detection Guidance

I don't know

Compliance Impact

I don't know

Mitigation Strategies

I don't know

Executive Summary

The OVRI Payment plugin for WordPress version 1.7.0 contains malicious .htaccess files. These files include directives that block the execution of certain scripts while allowing the execution of known malicious PHP files. If these .htaccess files are moved outside the plugin's directory, they can disrupt the normal functioning of the website.

Impact Analysis

This vulnerability can impact you by allowing malicious PHP files to execute on your WordPress site, potentially leading to unauthorized actions or disruptions. Additionally, if the malicious .htaccess files are moved outside the plugin directory, they may interfere with the proper operation of your website, causing functionality issues.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-10938. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart