The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives to prevent the execution of certain scripts while allowing execution of known malicious PHP files. If moved outside of the plugin's directory, they may interfere with the proper function of a site.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moneytigo
Moneytigo ovri Payment Wordpress Wordpress wordpress |
|
| Vendors & Products |
Moneytigo
Moneytigo ovri Payment Wordpress Wordpress wordpress |
Fri, 27 Feb 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives to prevent the execution of certain scripts while allowing execution of known malicious PHP files. If moved outside of the plugin's directory, they may interfere with the proper function of a site. | |
| Title | OVRI Payment 1.7.0 - Malicious .htaccess directive | |
| Weaknesses | CWE-506 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-02-27T09:23:42.427Z
Updated: 2026-02-27T16:15:28.956Z
Reserved: 2024-11-06T19:06:09.464Z
Link: CVE-2024-10938
Updated: 2026-02-27T16:12:50.384Z
Status : Awaiting Analysis
Published: 2026-02-27T10:16:18.957
Modified: 2026-02-27T14:06:37.987
Link: CVE-2024-10938
No data.