← WordPress Vulnerabilities
WordPress security by component

Realtyna Organic IDX plugin + WPL Real Estate

Realtyna Organic IDX plugin + WPL Real Estate is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: realtyna-organic-idx-plugin-wpl-real-estate

CVE-2026-13714: Realtyna WPL default API credentials permit executable uploads

Realtyna Organic IDX plugin + WPL Real Estate before 5.3.0 does not validate uploaded file types, while its API is enabled by default and accepts hardcoded credentials shared across installations. An unauthenticated attacker can use those known credentials to upload arbitrary PHP and execute it through the web server, resulting in full site compromise. The CNA record does not disclose the API endpoint, credential values, upload parameters or receiving function.

PublishedJul 27, 2026
Known safe version5.3.0
Safe version
Jul 27, 2026 CVE-2026-13714
Realtyna WPL default API credentials permit executable uploads
Realtyna Organic IDX plugin + WPL Real Estate before 5.3.0 does not validate uploaded file types, while its API is enabled by default and accepts hardcoded credentials shared across installations. An unauthenticated attacker can use those known credentials to upload arbitrary PHP and execute it through the web server, resulting in full site compromise. The CNA record does not disclose the API endpoint, credential values, upload parameters or receiving function.
5.3.0
CVE9.8
NVDPending