Atomic Edge Proof of Concept automated generator using AI diff analysis
Published : March 18, 2026

CVE-2024-10938: OVRI Payment 1.7.0 Malicious .htaccess directive PoC, Patch Analysis & Rule

Plugin moneytigo
Severity Medium (CVSS 6.5)
CWE 506
Vulnerable Version 1.7.0
Patched Version
Disclosed February 25, 2026

Analysis Overview

Atomic Edge analysis of CVE-2024-10938 (metadata-based):
This vulnerability is an instance of embedded malicious code (CWE-506). The OVRI Payment plugin version 1.7.0 contained one or more .htaccess files with malicious directives. These directives are designed to block the execution of legitimate scripts while explicitly allowing the execution of known malicious PHP files. The vulnerability description indicates the files are within the plugin’s directory. The risk arises if these files are moved to a higher-level directory, such as the site root, where they could affect the entire website’s behavior. The root cause is the intentional inclusion of harmful configuration files within the plugin’s distribution package. The exploitation method does not involve a remote attacker triggering a flaw. Instead, exploitation is contingent on the site administrator or a separate vulnerability moving the malicious .htaccess file. The impact is the disruption of normal site function and the potential execution of unauthorized PHP scripts, leading to integrity and availability loss. A fix requires the plugin author to release a clean version that removes the malicious files. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L) confirms network accessibility, low attack complexity, no privileges required, no user interaction, and impacts integrity and availability.

Frequently Asked Questions

Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet. Our AI inspection and analysis engine auto blocks threats before traditional firewall services can inspect, research and build archaic regex filters.

Get Started

Trusted by Developers & Organizations

Trusted by Developers
Black & McDonald logo representing Enterprise tier security and support for Atomic Edge WAF.Covenant House Toronto logo featuring a dove and text for Atomic Edge Enterprise planAlzheimer Society Canada logo representing trusted organizations and security partners.University of Toronto logo representing trusted organizations using Atomic Edge WAFSpecsavvers logo, trusted developers and organizations using Atomic Edge securityHarvard Medical School logo representing trusted organizations using Atomic Edge WAF.