CVE Vulnerabilities

CVE-2024-10938

Embedded Malicious Code

Published: Feb 27, 2026 | Modified: Feb 27, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives to prevent the execution of certain scripts while allowing execution of known malicious PHP files. If moved outside of the plugins directory, they may interfere with the proper function of a site.

Weakness

The product contains code that appears to be malicious in nature.

Potential Mitigations

References