Junglewise Threat Intelligence

CVE-2026-13714: Realtyna WPL Real Estate arbitrary file upload in API

CVE-2026-13714 · Severity: info · Published 2026-07-27

Vendors: Realtyna.

Executive brief

A vulnerability exists in the Realtyna Organic IDX and WPL Real Estate plugins for WordPress, which are used to manage real estate listings. Due to the use of universal hardcoded credentials and a lack of file type verification, an unauthorized person can upload malicious files to your website. This could allow an attacker to take complete control of the site, steal data, or disrupt business operations.

Technical details

The Realtyna Organic IDX and WPL Real Estate plugins (versions prior to 5.3.0) contain a critical flaw where file upload functionality is protected only by an API using hardcoded credentials that are identical across all installations. Furthermore, the plugin fails to validate the file types of uploaded content. An unauthenticated remote attacker can use these static credentials to access the API and upload arbitrary PHP files. Once uploaded, these files can be executed to achieve full Remote Code Execution (RCE) on the underlying web server. The issue is resolved in version 5.3.0.

Affected products

  • Realtyna Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0

Timeline

  • 2026-07-06: disclosed
  • 2026-07-27: advisory: NVD publication date
  • patched: Fixed in version 5.3.0

References

Related threats