Executive brief
A vulnerability exists in the Realtyna Organic IDX and WPL Real Estate plugins for WordPress, which are used to manage real estate listings. Due to the use of universal hardcoded credentials and a lack of file type verification, an unauthorized person can upload malicious files to your website. This could allow an attacker to take complete control of the site, steal data, or disrupt business operations.
Technical details
The Realtyna Organic IDX and WPL Real Estate plugins (versions prior to 5.3.0) contain a critical flaw where file upload functionality is protected only by an API using hardcoded credentials that are identical across all installations. Furthermore, the plugin fails to validate the file types of uploaded content. An unauthenticated remote attacker can use these static credentials to access the API and upload arbitrary PHP files. Once uploaded, these files can be executed to achieve full Remote Code Execution (RCE) on the underlying web server. The issue is resolved in version 5.3.0.
Affected products
- Realtyna Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0
Timeline
- 2026-07-06: disclosed
- 2026-07-27: advisory: NVD publication date
- patched: Fixed in version 5.3.0