The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing authentication check on the REST API import endpoint. This makes it possible for authenticate [truncated]
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by static, plugin-seeded API credentials that are identical across all installations. This [truncated]
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 has a vulnerability that allows unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution. This is due to the file upload functionality being gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. The vulnerabili [truncated]
The CVE-2026-57811 vulnerability is an Improper Control of Generation of Code ('Code Injection') issue, also known as Remote Code Inclusion, in the Realtyna Organic IDX plugin for WordPress. This critical vulnerability affects versions from n/a through <= 5.2.0 and has a CVSS score of 10. Users should be aware of the potential for remote code execution and take immediate action to mitigate the risk. The C [truncated]
CVE-2026-45439 is a critical unauthenticated SQL injection vulnerability in the Realtyna Organic IDX plugin versions <= 5.1.0. The vulnerability has a CVSS score of 9.3, indicating a high severity. The CVE was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-45439) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-45439).