Junglewise Threat Intelligence

CVE-2026-16236: Realtyna Organic IDX arbitrary file upload in saveLiveImages

CVE-2026-16236 · Severity: high · CVSS 8.8 · Published 2026-07-31

Executive brief

The Realtyna Organic IDX plugin for WordPress, which is used to integrate real estate listings into websites, contains a security flaw that allows users with basic account access to upload malicious files. An attacker could use this to take full control of the website's server, potentially leading to data theft or a complete site shutdown. This affects all versions of the plugin up to and including 5.3.0.

Technical details

The Realtyna Organic IDX plugin for WordPress is vulnerable to unrestricted file uploads due to missing file extension and content validation in the saveLiveImages() function. This is exacerbated by an insufficient authorization check on the get_keys() AJAX handler and a missing authentication check on the REST API import endpoint. Authenticated attackers with subscriber-level permissions or higher can exploit these weaknesses to upload arbitrary files, such as PHP scripts, to the server. Successful exploitation can lead to remote code execution (RCE) and full system compromise. The vulnerability exists in all versions up to and including 5.3.0.

Affected products

  • Realtyna Organic IDX plugin + WPL Real Estate up to, and including, 5.3.0

Timeline

  • 2026-07-31: disclosed
  • 2026-07-31: advisory

References