
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-10938 is an Embedded Malicious Code vulnerability (CWE-506) affecting the OVRI Payment plugin for WordPress, specifically version 1.7.0. The plugin was found to contain malicious .htaccess files that prevent execution of certain legitimate scripts while allowing execution of known malicious PHP files. If these files are moved outside the plugin's directory, they may further disrupt site functionality. The vulnerability was published on February 27, 2026, with Wordfence credited as the assigner, and carries a CVSS v3.1 base score of 6.5 (Medium) (Wordfence, ENISA EUVD).
The root cause is the deliberate inclusion of malicious .htaccess files within the OVRI Payment (moneytigo) plugin package, classified as CWE-506 (Embedded Malicious Code). Two malicious files were identified: one in the plugin root (/tags/1.7.0/.htaccess) and one in the assets directory (/tags/1.7.0/assets/.htaccess). These files contain Apache directives designed to block execution of certain scripts while whitelisting known malicious PHP files, effectively creating a backdoor-friendly environment on the web server. No authentication or user interaction is required to be affected by the presence of these files, as the malicious directives take effect automatically when Apache processes the directory (Wordfence, WordPress Plugin Trac).
The primary impact is on the integrity and availability of affected WordPress sites. The malicious .htaccess directives can allow attackers to execute pre-planted malicious PHP files that would otherwise be blocked, while simultaneously preventing legitimate security scripts from running. If the .htaccess files propagate outside the plugin directory (e.g., to the web root), they can disrupt the normal operation of the entire WordPress site and potentially enable persistent code execution by a threat actor who has already placed malicious PHP files on the server (Wordfence, ENISA EUVD).
The EPSS score for CVE-2024-10938 is approximately 0.048% (0.000480), indicating a low probability of active exploitation in the near term (Feedly). No public exploit code, exploit kits, or confirmed in-the-wild exploitation campaigns have been reported. The vulnerability does not require authentication or user interaction, but exploitation depends on the attacker having already placed malicious PHP files on the server, limiting its standalone exploitability. There is no current listing in the CISA Known Exploited Vulnerabilities (KEV) catalog.
.htaccess files to the plugin and assets directories..htaccess files, applying directives that block certain legitimate scripts and whitelist specific malicious PHP filenames for execution..htaccess directives..htaccess files are copied or moved to the web root (e.g., during plugin updates or file operations), the malicious directives affect the entire site, broadening the attacker's foothold (Wordfence, WordPress Plugin Trac)..htaccess files in wp-content/plugins/moneytigo/ or wp-content/plugins/moneytigo/assets/ containing directives that allow execution of specific PHP filenames or block security scripts; unexpected .htaccess files in the WordPress web root with similar directives..htaccess rules..htaccess deny rules (Wordfence, WordPress Plugin Trac).Site administrators should immediately remove or deactivate the OVRI Payment (moneytigo) plugin version 1.7.0 and delete all associated files, including the malicious .htaccess files from the plugin and assets directories. Inspect the WordPress web root and all directories for any unexpected .htaccess files or unknown PHP files that may have been introduced. As of the disclosure date, no patched version of the plugin has been confirmed; administrators should avoid reinstalling the plugin until a clean version is verified. Conduct a full site integrity check using a WordPress security scanner to identify any additional malicious files (Wordfence).
Wordfence, which discovered and reported the vulnerability, published a threat intelligence entry detailing the malicious .htaccess files and their behavior. The vulnerability was also noted by ENISA's European Vulnerability Database (EUVD) and referenced by security aggregators including Vulners, VulDB, and CIRCL. Community discussion appears limited, with a brief mention on Bluesky's CVE feed and coverage by security news aggregators (Wordfence, ENISA EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."