VYPR

Realtyna Organic IDX plugin + WPL Real Estate

by WordPress

CVEs (3)

  • CVE-2026-14483CriJul 31, 2026
    risk 0.64cvss 9.8epss 0.04

    The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly…

  • CVE-2026-91014HigSep 17, 2026
    risk 0.46cvss 7.1epss 0.00

    The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run arbitrary web scripts in a visitor's browser if they can trick…

  • CVE-2026-13714CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.01

    The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically…