CVE-2026-13714
A flaw in the Realtyna Organic IDX and WPL Real Estate WordPress plugins lets attackers upload any PHP file without validation, enabling remote code execution. The vulnerability exists in versions before 5.3.0 and is triggered by an API that uses default hardcoded credentials.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of the Realtyna Organic IDX plugin and WPL Real Estate WordPress plugin running versions earlier than 5.3.0 on WordPress sites.
Real-world impact
An attacker could upload malicious PHP files and run arbitrary code on the affected WordPress site, potentially taking full control of the server.
Why this severity
The CVSS score of 9.8 reflects that the flaw is exploitable over the network, requires no privileges or user interaction, and gives the attacker full confidentiality, integrity, and availability compromise.
What to do about it
- 01Upgrade the Realtyna Organic IDX plugin and WPL Real Estate WordPress plugin to version 5.3.0 or later.
NVD description
Timeline
- Jul 27, 2026 · 5d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 27, 2026 · 4d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.