Realtyna Organic IDX/WPL <= 5.2.0 - Unauthenticated Arbitrary File Upload
CVE-2026-14483
Verified
Description
Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress <= 5.2.0 contains an unrestricted file upload vulnerability caused by missing file type validation and static API credentials, letting unauthenticated attackers upload executable files and achieve remote code execution, exploit requires knowledge of static API credentials.
Severity
Critical
CVSS Score
9.8
Exploit Probability
4%
Affected Product
real-estate-listing-realtyna-wpl
Published Date
August 11, 2026
Template Author
str4k3r
CVE-2026-14483.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-14483
CWE ID:
cwe-434
Remediation Steps
Update to a version later than 5.2.0 or apply patches that enforce proper file validation and unique API credentials.