top of page
perceptive_background_267k.jpg

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality …

Published:

26 juli 2026 om 22:00:00

Alert date:

27 juli 2026 om 21:04:07

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

CVE-2026-13714 affects the Realtyna Organic IDX plugin combined with WPL Real Estate WordPress plugin before version 5.3.0. The plugin fails to validate uploaded file types, allowing arbitrary PHP file uploads. The file upload API is enabled by default and uses hardcoded credentials that are identical across all installations. This effectively means any unauthenticated attacker can leverage the hardcoded credentials to access the API. Successful exploitation leads to remote code execution on the affected WordPress site. All installations prior to version 5.3.0 are vulnerable. The vulnerability is rated high severity due to its unauthenticated nature and direct RCE impact.

Technical details

Mitigation steps:

Affected products:

Realtyna Organic IDX plugin
WPL Real Estate WordPress plugin

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page