Realtyna Organic IDX plugin + WPL Real Estate <= 5.3.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command
critical
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.3.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by...
- CVSS:
- 9.8
- Affected:
- up to 5.3.0
- Fixed in:
- 5.4.0
- Disclosed:
- Jul 30, 2026
CVE-2026-14483 on NVD →
Realtyna Organic IDX plugin + WPL Real Estate <= 5.3.0 - Authenticated (Subscriber+) Arbitrary File Upload
high
The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing authe...
- CVSS:
- 8.8
- Affected:
- up to 5.3.0
- Fixed in:
- 5.4.0
- Disclosed:
- Jul 30, 2026
CVE-2026-16236 on NVD →
Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Remote Code Execution
critical
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.2.0. This makes it possible for unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 5.2.0
- Fixed in:
- 5.3.0
- Disclosed:
- Jul 9, 2026
CVE-2026-57811 on NVD →
Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload
critical
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 5.2.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remo...
- CVSS:
- 9.8
- Affected:
- up to 5.2.0
- Fixed in:
- 5.3.0
- Disclosed:
- Jul 6, 2026
CVE-2026-13714 on NVD →
Realtyna Organic IDX plugin + WPL Real Estate <= 5.1.0 - Unauthenticated SQL Injection
high
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to...
- CVSS:
- 7.5
- Affected:
- up to 5.1.0
- Fixed in:
- 5.2.0
- Disclosed:
- May 26, 2026
CVE-2026-45439 on NVD →
Realtyna Organic IDX plugin <= 5.0.0 - Unauthenticated Local File Inclusion
high
The Realtyna Organic IDX plugin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.0.0. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass...
- CVSS:
- 8.1
- Affected:
- up to 5.0.0
- Fixed in:
- 5.0.1
- Disclosed:
- Jul 30, 2025
CVE-2025-54052 on NVD →
Realtyna Organic IDX plugin <= 4.14.13 - Authenticated (Admin+) Arbitrary File Upload
critical
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.14.13. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make re...
- CVSS:
- 9.1
- Affected:
- up to 4.14.13
- Fixed in:
- 4.14.14
- Disclosed:
- Jul 11, 2024
CVE-2024-38736 on NVD →
Realtyna Organic IDX plugin <= 4.14.4 - Reflected Cross-Site Scripting
medium
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.14.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- CVSS:
- 6.1
- Affected:
- up to 4.14.4
- Fixed in:
- 4.14.8
- Disclosed:
- Apr 29, 2024
CVE-2024-33924 on NVD →
Realtyna Organic IDX plugin <= 4.14.4 - Unauthenticated SQL Injection
critical
The Realtyna Organic IDX plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.14.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additiona...
- CVSS:
- 10
- Affected:
- up to 4.14.4
- Fixed in:
- 4.14.8
- Disclosed:
- Apr 12, 2024
CVE-2024-32128 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database