WordPress security by component
Realtyna Organic IDX plugin + WPL Real Estate
Plugin description
Realtyna Organic IDX plugin + WPL Real Estate is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
realtyna-organic-idx-plugin-wpl-real-estateLatest vulnerability
CVE-2026-13714: Realtyna WPL default API credentials permit executable uploads
Realtyna Organic IDX plugin + WPL Real Estate before 5.3.0 does not validate uploaded file types, while its API is enabled by default and accepts hardcoded credentials shared across installations. An unauthenticated attacker can use those known credentials to upload arbitrary PHP and execute it through the web server, resulting in full site compromise. The CNA record does not disclose the API endpoint, credential values, upload parameters or receiving function.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-13714
Realtyna WPL default API credentials permit executable uploads
Realtyna Organic IDX plugin + WPL Real Estate before 5.3.0 does not validate uploaded file types, while its API is enabled by default and accepts hardcoded credentials shared across installations. An unauthenticated attacker can use those known credentials to upload arbitrary PHP and execute it through the web server, resulting in full site compromise. The CNA record does not disclose the API endpoint, credential values, upload parameters or receiving function.
|
5.3.0 |
CVE9.8
NVDPending
|