


Perceptive Security
SOC/SIEM Consultancy

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via th…
Published:
30 juli 2026 om 22:00:00
Alert date:
31 juli 2026 om 08:00:57
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities, Identity & Access
The Realtyna Organic IDX + WPL Real Estate plugin for WordPress (versions up to and including 5.2.0) is vulnerable to arbitrary file upload leading to remote code execution. The vulnerability stems from missing file type validation in the upload function and a publicly accessible I/O endpoint that uses static, hardcoded API credentials identical across all installations. The WPL I/O service endpoint is registered on the public WordPress init hook with no capability checks, making it accessible to unauthenticated attackers. The required api_key and api_secret values are static defaults seeded by the plugin's own SQL migration files and are publicly documented. Any unauthenticated attacker with knowledge of these default credentials can upload executable files and achieve remote code execution on affected WordPress installations. The combination of missing authentication controls and lack of file type validation makes this a critical, easily exploitable vulnerability.
Technical details
Mitigation steps:
Affected products:
Realtyna Organic IDX plugin
WPL Real Estate plugin for WordPress
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-14483
https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/trunk/assets/migrations/basic/1.0.0.sql#L1119
https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/trunk/libraries/file.php#L217
https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/trunk/libraries/io/global.php#L142
https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/trunk/libraries/io/mobile_application/set_property.php#L39
https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/trunk/libraries/services/io.php#L20
https://www.wordfence.com/threat-intel/vulnerabilities/id/23068a98-623d-4eb3-a7c5-6af410de4320?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
