WordPress · Organic Idx · CVE-2026-13714
**Name of the Vulnerable Software and Affected Versions**
Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin versions prior to 5.3.0
**Description**
The software fails to validate the type of uploaded files. The file upload functionality is protected by an API that is enabled by default and uses hardcoded credentials that are identical across all installations. This allows unauthenticated attackers to upload arbitrary PHP files, leading to remote code execution (RCE), which is the ability to execute malicious commands on the server.
**Recommendations**
Update Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin to version 5.3.0 or later.