Arbitrary File Upload Vulnerability in Realtyna Organic IDX Plugin for WordPress
CVE-2026-16236

8.8HIGH

What is CVE-2026-16236?

The Realtyna Organic IDX plugin for WordPress contains a vulnerability allowing authenticated attackers with subscriber-level access and higher to upload arbitrary files to the server. This issue arises from inadequate validation of file extensions and content within the 'saveLiveImages()' function, alongside insufficient authorization checks on the 'get_keys()' AJAX handler and missing authentication for the REST API import endpoint. This vulnerability can potentially lead to remote code execution, posing significant risks to affected WordPress sites.

Affected Version(s)

Realtyna Organic IDX plugin + WPL Real Estate 0 <= 5.3.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Son Van (mrs0x06)
.