plugin

Real Estate Listing Realtyna Wpl Vulnerabilities

9 known security issues reported for the Real Estate Listing Realtyna Wpl WordPress plugin. Most recent disclosed Jul 30, 2026.

5 critical 3 high 1 medium

Running Real Estate Listing Realtyna Wpl on your site? Check whether your installed version is affected.

Scan your site free

Realtyna Organic IDX plugin + WPL Real Estate <= 5.3.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command

critical

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.3.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by...

CVSS:
9.8
Affected:
up to 5.3.0
Fixed in:
5.4.0
Disclosed:
Jul 30, 2026

CVE-2026-14483 on NVD →

Realtyna Organic IDX plugin + WPL Real Estate <= 5.3.0 - Authenticated (Subscriber+) Arbitrary File Upload

high

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing authe...

CVSS:
8.8
Affected:
up to 5.3.0
Fixed in:
5.4.0
Disclosed:
Jul 30, 2026

CVE-2026-16236 on NVD →

Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Remote Code Execution

critical

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.2.0. This makes it possible for unauthenticated attackers to execute code on the server.

CVSS:
9.8
Affected:
up to 5.2.0
Fixed in:
5.3.0
Disclosed:
Jul 9, 2026

CVE-2026-57811 on NVD →

Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload

critical

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 5.2.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remo...

CVSS:
9.8
Affected:
up to 5.2.0
Fixed in:
5.3.0
Disclosed:
Jul 6, 2026

CVE-2026-13714 on NVD →

Realtyna Organic IDX plugin + WPL Real Estate <= 5.1.0 - Unauthenticated SQL Injection

high

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to...

CVSS:
7.5
Affected:
up to 5.1.0
Fixed in:
5.2.0
Disclosed:
May 26, 2026

CVE-2026-45439 on NVD →

Realtyna Organic IDX plugin <= 5.0.0 - Unauthenticated Local File Inclusion

high

The Realtyna Organic IDX plugin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.0.0. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass...

CVSS:
8.1
Affected:
up to 5.0.0
Fixed in:
5.0.1
Disclosed:
Jul 30, 2025

CVE-2025-54052 on NVD →

Realtyna Organic IDX plugin <= 4.14.13 - Authenticated (Admin+) Arbitrary File Upload

critical

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.14.13. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make re...

CVSS:
9.1
Affected:
up to 4.14.13
Fixed in:
4.14.14
Disclosed:
Jul 11, 2024

CVE-2024-38736 on NVD →

Realtyna Organic IDX plugin <= 4.14.4 - Reflected Cross-Site Scripting

medium

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.14.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

CVSS:
6.1
Affected:
up to 4.14.4
Fixed in:
4.14.8
Disclosed:
Apr 29, 2024

CVE-2024-33924 on NVD →

Realtyna Organic IDX plugin <= 4.14.4 - Unauthenticated SQL Injection

critical

The Realtyna Organic IDX plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.14.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additiona...

CVSS:
10
Affected:
up to 4.14.4
Fixed in:
4.14.8
Disclosed:
Apr 12, 2024

CVE-2024-32128 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database