Cross Site Scripting Vulnerability in Realtyna Organic IDX Plugin by Realtyna
CVE-2026-78261

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 August 2026

What is CVE-2026-78261?

The Realtyna Organic IDX plugin for WordPress is prone to an unauthenticated Cross Site Scripting (XSS) vulnerability. This flaw affects versions of the plugin up to 5.4.1, allowing attackers to inject malicious scripts into web pages viewed by other users. Successful exploitation can lead to unauthorized actions, data theft, and a compromised user experience. Website administrators should take immediate steps to patch affected versions and safeguard their sites.

Affected Version(s)

Realtyna Organic IDX plugin <= 5.4.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aydan Arabadzha | Patchstack Bug Bounty Program
.