top of page
perceptive_background_267k.jpg

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via th…

Published:

31 July 2026 at 00:00:00

Alert date:

31 July 2026 at 10:00:57

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities, Identity & Access

The Realtyna Organic IDX + WPL Real Estate plugin for WordPress (versions up to and including 5.2.0) is vulnerable to arbitrary file upload leading to remote code execution. The vulnerability stems from missing file type validation in the upload function and a publicly accessible I/O endpoint that uses static, hardcoded API credentials identical across all installations. The WPL I/O service endpoint is registered on the public WordPress init hook with no capability checks, making it accessible to unauthenticated attackers. The required api_key and api_secret values are static defaults seeded by the plugin's own SQL migration files and are publicly documented. Any unauthenticated attacker with knowledge of these default credentials can upload executable files and achieve remote code execution on affected WordPress installations. The combination of missing authentication controls and lack of file type validation makes this a critical, easily exploitable vulnerability.

Technical details

Mitigation steps:

Affected products:

Realtyna Organic IDX plugin
WPL Real Estate plugin for WordPress

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page