Realtyna Organic IDX Plugin Vulnerable to SQL Injection
CVE-2024-32128

9.3CRITICAL

Key Information:

Vendor
WordPress
Vendor
CVE Published:
15 April 2024

Summary

The Realtyna Organic IDX plugin exhibits a vulnerability due to improper neutralization of special elements within an SQL command, leading to a SQL Injection issue. This vulnerability can potentially allow an attacker to manipulate SQL queries, gaining unauthorized access to sensitive data or executing arbitrary SQL commands. It specifically impacts all versions of the Realtyna Organic IDX plugin prior to 4.14.4, posing significant risks to users who have not updated to the latest version. Security measures are essential to mitigate the exploitation of this vulnerability.

Affected Version(s)

Realtyna Organic IDX plugin <= 4.14.4

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joshua Chan (Patchstack Alliance)
.