A security flaw has been identified in the Realtyna Organic IDX and WPL Real Estate plugins for WordPress, affecting all versions up to and including 5.2.0. The issue exists in the plugins’ file upload feature, which does not verify the type of file a user is attempting to upload.
This upload feature is secured only by default, identical API credentials that are publicly documented and pre-seeded for every installation of the plugin, with no permission checks to stop unauthenticated visitors from accessing it. As a result, anyone can upload files to your site without logging in, including files that can execute code on your web server. If this flaw is exploited, an attacker could take control of your website, access private data stored on your site, or disrupt your site’s normal functionality.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14483