Executive brief
A critical security flaw has been identified in the Realtyna Organic IDX plugin, a tool used by real estate websites to display property listings. This vulnerability allows an unauthorized attacker to remotely execute malicious code on the website's server. If exploited, an attacker could gain full control over the website, potentially leading to the theft of sensitive customer data, site defacement, or the installation of ransomware.
Technical details
The Realtyna Organic IDX plugin (real-estate-listing-realtyna-wpl) through version 5.2.0 contains an Improper Control of Generation of Code ('Code Injection') vulnerability (CWE-94). This flaw allows an unauthenticated remote attacker to perform Remote Code Inclusion/Execution (RCE) by injecting malicious code into the application. The vulnerability has a CVSS score of 10.0, indicating it is easily exploitable over the network without user interaction. Attackers can leverage this to gain a backdoor, escalate privileges, and achieve full system compromise. A fix is available in version 5.3.0.
Affected products
- Realtyna Realtyna Organic IDX plugin (real-estate-listing-realtyna-wpl) <= 5.2.0
Timeline
- 2026-06-03: other: Reported by ParkHyunWoo
- 2026-07-09: advisory: Patchstack advisory published
- 2026-07-13: disclosed: CVE published to NVD