PT-2026-22327 · WordPress · Ovri Payment Plugin
Marco Wotschka
·
Published
2026-02-27
·
Updated
2026-02-27
·
CVE-2024-10938
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
OVRI Payment plugin for WordPress version 1.7.0
Description
The software includes malicious .htaccess files in version 1.7.0. These files contain directives designed to prevent the execution of specific scripts while permitting the execution of known malicious PHP files. If these files are moved from the plugin’s directory, they could disrupt the normal operation of a website. The .htaccess files are used to control access to specific files and directories on the web server.
Recommendations
Update to a newer version that contains a fix for this vulnerability.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ovri Payment Plugin