The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives to prevent the execution of certain scripts while allowing execution of known malicious PHP files. If moved outside of the plugin's directory, they may interfere with the proper function of a site.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-02-27 10:16
Updated : 2026-02-27 14:06
NVD link : CVE-2024-10938
Mitre link : CVE-2024-10938
CVE.ORG link : CVE-2024-10938
JSON object : View
Products Affected
No product.
CWE
CWE-506
Embedded Malicious Code
