CVE-2026-14483 (matched: wordpress)

  • Friday, 31st July, 2026
  • 10:05am

A security vulnerability has been identified in two WordPress real estate plugins: the Realtyna Organic IDX plugin and the WPL Real Estate plugin. All versions of these plugins up to and including version 5.2.0 are affected by this flaw. The issue exists in the plugins’ file upload feature, which does not verify what type of file a user is attempting to add. The security credentials required to access this upload feature are identical, pre-set default values for every site running these plugins, and no login or special access is needed to reach the vulnerable upload path. These default credentials are publicly documented, so any unauthenticated attacker can access the feature. Exploiting this flaw lets attackers upload executable files to your website, which allows them to run unauthorized code on your site. This could lead to your site being damaged, sensitive data being stolen, or your site being used to harm visitors who access it.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14483

« Back