


Perceptive Security
SOC/SIEM Consultancy

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality …
Published:
26 juli 2026 om 22:00:00
Alert date:
27 juli 2026 om 21:04:07
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
CVE-2026-13714 affects the Realtyna Organic IDX plugin combined with WPL Real Estate WordPress plugin before version 5.3.0. The plugin fails to validate uploaded file types, allowing arbitrary PHP file uploads. The file upload API is enabled by default and uses hardcoded credentials that are identical across all installations. This effectively means any unauthenticated attacker can leverage the hardcoded credentials to access the API. Successful exploitation leads to remote code execution on the affected WordPress site. All installations prior to version 5.3.0 are vulnerable. The vulnerability is rated high severity due to its unauthenticated nature and direct RCE impact.
Technical details
Mitigation steps:
Affected products:
Realtyna Organic IDX plugin
WPL Real Estate WordPress plugin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-13714
https://wpscan.com/vulnerability/69f9dcd8-ab3c-46ed-ac6b-2f1db35f8d1f/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
