Description

The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives to prevent the execution of certain scripts while allowing execution of known malicious PHP files. If moved outside of the plugin's directory, they may interfere with the proper function of a site.

INFO

Published Date :

2026-02-27T09:23:42.427Z

Last Modified :

2026-02-27T16:15:28.956Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2024-10938 vulnerability.

Vendors Products
Moneytigo
  • Ovri Payment
Wordpress
  • Wordpress

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact