Junglewise Threat Intelligence

CVE-2026-45439: Realtyna Organic IDX plugin unauthenticated SQL injection

CVE-2026-45439 · Severity: critical · CVSS 9.3 · Published 2026-06-15

Vendors: Realtyna.

Executive brief

The Realtyna Organic IDX plugin for WordPress, which is used to manage real estate listings and property data, contains a critical security flaw. This vulnerability allows an unauthenticated attacker to interact directly with the website's database without needing a password. An exploit could lead to the theft of sensitive customer information, unauthorized access to site data, or disruption of business operations.

Technical details

A SQL injection vulnerability exists in the Realtyna Organic IDX (WPL) plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is accessible to unauthenticated remote attackers over the network with low attack complexity. By sending specially crafted requests, an attacker can execute arbitrary SQL queries against the backend database. This can result in full data exfiltration, modification of database records, or impact on service availability. The issue is resolved in version 5.2.0.

Affected products

  • Realtyna Organic IDX plugin (WPL) <= 5.1.0

Timeline

  • 2026-05-09: other: Reported by researcher ParkHyunWoo
  • 2026-05-26: advisory: Initial advisory published by Patchstack
  • 2026-06-15: disclosed: CVE published to NVD
  • 2026-05-26: patched: Version 5.2.0 released to address the vulnerability

References