CVE-2024-10938: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2024-10938 is an Embedded Malicious Code vulnerability (CWE-506) affecting the OVRI Payment plugin for WordPress, specifically version 1.7.0. The plugin was found to contain malicious .htaccess files that prevent execution of certain legitimate scripts while allowing execution of known malicious PHP files. If these files are moved outside the plugin's directory, they may further disrupt site functionality. The vulnerability was published on February 27, 2026, with Wordfence credited as the assigner, and carries a CVSS v3.1 base score of 6.5 (Medium) (Wordfence, ENISA EUVD).

Technical details

The root cause is the deliberate inclusion of malicious .htaccess files within the OVRI Payment (moneytigo) plugin package, classified as CWE-506 (Embedded Malicious Code). Two malicious files were identified: one in the plugin root (/tags/1.7.0/.htaccess) and one in the assets directory (/tags/1.7.0/assets/.htaccess). These files contain Apache directives designed to block execution of certain scripts while whitelisting known malicious PHP files, effectively creating a backdoor-friendly environment on the web server. No authentication or user interaction is required to be affected by the presence of these files, as the malicious directives take effect automatically when Apache processes the directory (Wordfence, WordPress Plugin Trac).

Impact

The primary impact is on the integrity and availability of affected WordPress sites. The malicious .htaccess directives can allow attackers to execute pre-planted malicious PHP files that would otherwise be blocked, while simultaneously preventing legitimate security scripts from running. If the .htaccess files propagate outside the plugin directory (e.g., to the web root), they can disrupt the normal operation of the entire WordPress site and potentially enable persistent code execution by a threat actor who has already placed malicious PHP files on the server (Wordfence, ENISA EUVD).

Exploitability

The EPSS score for CVE-2024-10938 is approximately 0.048% (0.000480), indicating a low probability of active exploitation in the near term (Feedly). No public exploit code, exploit kits, or confirmed in-the-wild exploitation campaigns have been reported. The vulnerability does not require authentication or user interaction, but exploitation depends on the attacker having already placed malicious PHP files on the server, limiting its standalone exploitability. There is no current listing in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Plugin Installation: A site administrator installs the OVRI Payment plugin version 1.7.0 from the WordPress plugin repository, which deploys the malicious .htaccess files to the plugin and assets directories.
  2. Malicious Directives Activated: Apache automatically processes the .htaccess files, applying directives that block certain legitimate scripts and whitelist specific malicious PHP filenames for execution.
  3. Malicious PHP Placement: An attacker (who may have separate write access, or who planted files prior to the plugin install) places malicious PHP files in locations whitelisted by the .htaccess directives.
  4. Execution: The attacker accesses the whitelisted malicious PHP files via HTTP, achieving code execution on the server while legitimate security scripts remain blocked.
  5. Persistence/Lateral Movement: If the .htaccess files are copied or moved to the web root (e.g., during plugin updates or file operations), the malicious directives affect the entire site, broadening the attacker's foothold (Wordfence, WordPress Plugin Trac).

Indicators of compromise

  • File System: Presence of .htaccess files in wp-content/plugins/moneytigo/ or wp-content/plugins/moneytigo/assets/ containing directives that allow execution of specific PHP filenames or block security scripts; unexpected .htaccess files in the WordPress web root with similar directives.
  • File System: Presence of unknown or suspicious PHP files in the plugin directory or web root that match filenames whitelisted by the malicious .htaccess rules.
  • Logs: Apache/Nginx access logs showing HTTP requests to unusual PHP files within the plugin directory, especially files not part of the standard plugin codebase.
  • Logs: Error logs showing blocked execution of legitimate WordPress or security plugin scripts due to .htaccess deny rules (Wordfence, WordPress Plugin Trac).

Mitigation and workarounds

Site administrators should immediately remove or deactivate the OVRI Payment (moneytigo) plugin version 1.7.0 and delete all associated files, including the malicious .htaccess files from the plugin and assets directories. Inspect the WordPress web root and all directories for any unexpected .htaccess files or unknown PHP files that may have been introduced. As of the disclosure date, no patched version of the plugin has been confirmed; administrators should avoid reinstalling the plugin until a clean version is verified. Conduct a full site integrity check using a WordPress security scanner to identify any additional malicious files (Wordfence).

Community reactions

Wordfence, which discovered and reported the vulnerability, published a threat intelligence entry detailing the malicious .htaccess files and their behavior. The vulnerability was also noted by ENISA's European Vulnerability Database (EUVD) and referenced by security aggregators including Vulners, VulDB, and CIRCL. Community discussion appears limited, with a brief mention on Bluesky's CVE feed and coverage by security news aggregators (Wordfence, ENISA EUVD).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management