CVE-2026-13714 Details
Description
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.
A vulnerability exists in the Realtyna Organic IDX plugin and the WPL Real Estate WordPress plugin, affecting versions prior to 5.3.0. The issue arises because the plugins do not properly validate uploaded files. The file upload feature is controlled by an API that is enabled by default and authenticated with hardcoded credentials that are the same across all installations. This flaw allows unauthenticated attackers to upload arbitrary PHP files, potentially leading to remote code execution.
Users are advised to update to Realtyna Organic IDX and WPL Real Estate WordPress plugins version 5.3.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 27, 2026CISA-ADP
Assessed Jul 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/69f9dcd8-ab3c-46ed-ac6b-2f1db35f8d1f/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Realtyna Organic IDX | < 5.3.0 (semver) |
CPE
Remediation
| |
| Realtyna WPL Real Estate | < 5.3.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | CVE Modified | CISA-ADP |
| Jul 27, 2026 | New CVE Received | [email protected] |
Volerion