Back to overview

CVE-2026-13714

Description
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.

Metadata

CVE ID
CVE-2026-13714
State
PUBLISHED
Assigner
WPScan
Reserved
2026-06-29 14:01 UTC
Published
2026-07-27 06:00 UTC
Last updated
2026-07-27 06:00 UTC
Vendor / Product
Unknown / Realtyna Organic IDX plugin + WPL Real Estate
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown Realtyna Organic IDX plugin + WPL Real Estate 0 < 5.3.0
Weakness (CWE)
CWESourceDescription
cna CWE-434 Unrestricted Upload of File with Dangerous Type
Back to overview