Junglewise Threat Intelligence

CVE-2026-78261: Realtyna Organic IDX cross-site scripting

CVE-2026-78261 · Severity: high · CVSS 7.1 · Published 2026-08-27

Vendors: Realtyna.

Executive brief

The Realtyna Organic IDX WordPress plugin, used to display real estate listings on websites, contains an unauthenticated cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in visitors' browsers, enabling account hijacking, credential theft, or malware distribution without requiring any authentication or special privileges.

Technical details

The vulnerability is a reflected or stored cross-site scripting (XSS) flaw in the Realtyna Organic IDX plugin versions 5.4.1 and earlier that allows unauthenticated attackers to inject arbitrary JavaScript. The attack requires user interaction (e.g., a victim clicking a malicious link or visiting a crafted page), but no authentication is needed to initiate the attack. Successful exploitation allows attackers to steal visitor session cookies, perform actions on behalf of users, capture sensitive data, or redirect users to malicious sites. The vulnerability has been patched in version 5.4.2 and later.

Affected products

  • Realtyna Organic IDX <= 5.4.1

Timeline

  • 2026-08-27: disclosed: Published by Patchstack
  • 2026-08-25: patched: Version 5.4.2 released

References