Arbitrary File Upload Vulnerability in Realtyna Organic IDX Plugin for WordPress
CVE-2026-16236
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 July 2026
What is CVE-2026-16236?
The Realtyna Organic IDX plugin for WordPress contains a vulnerability allowing authenticated attackers with subscriber-level access and higher to upload arbitrary files to the server. This issue arises from inadequate validation of file extensions and content within the 'saveLiveImages()' function, alongside insufficient authorization checks on the 'get_keys()' AJAX handler and missing authentication for the REST API import endpoint. This vulnerability can potentially lead to remote code execution, posing significant risks to affected WordPress sites.
Affected Version(s)
Realtyna Organic IDX plugin + WPL Real Estate 0 <= 5.3.0