Junglewise Threat Intelligence

CVE-2026-91014: Realtyna Organic IDX + WPL Real Estate reflected XSS in location selector

CVE-2026-91014 · Severity: high · CVSS 7.1 · Published 2026-09-17

Vendors: Realtyna.

Executive brief

The Realtyna Organic IDX + WPL Real Estate WordPress plugin is used to display and manage real estate listings on websites. A reflected cross-site scripting (XSS) vulnerability allows attackers to inject malicious scripts that execute in visitors' browsers when they click a crafted link, potentially compromising visitor data, hijacking sessions, or redirecting users to malicious sites.

Technical details

The plugin fails to properly sanitize and escape parameters before reflecting them back in HTTP responses, creating a reflected XSS vulnerability in the location selector endpoint. An unauthenticated attacker can craft a malicious URL containing JavaScript payloads that will execute in a victim's browser when the link is visited. No authentication is required to exploit this vulnerability. The vendor has released a patch in version 5.4.2 that sanitizes and escapes the vulnerable parameters.

Affected products

  • Realtyna Organic IDX + WPL Real Estate before 5.4.2

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in version 5.4.2

References