What is CVE-2026-13714?
CVE-2026-13714 is a vulnerability in the Realtyna Organic IDX + WPL Real Estate WordPress plugin before version 5.3.0, where file upload functionality lacks type validation and relies on a default-enabled API authenticated with hardcoded credentials identical across all installations. This allows bypassing authentication to upload arbitrary files. Immediate update to version 5.3.0 or above is recommended.
Azərbaycanca: CVE-2026-13714, Realtyna Organic IDX + WPL Real Estate WordPress plugin-in 5.3.0-dan əvvəlki versiyalarında fayl yükləmə funksionallığında tip yoxlamasının olmaması və standart olaraq aktiv olan API ilə qorunan, lakin bütün qurğularda eyni olan sabit kodlaşdırılmış etimadnamələrlə autentifikasiya edilən zəiflikdir. Bu boşluq autentifikasiyanı keçərək ixtiyari fayl yükləməsinə imkan verir. Ən qısa zamanda plaqini 5.3.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-798
FAQ1
How does CVE-2026-13714 allow bypassing authentication in the Realtyna plugin?
The vulnerability allows bypassing authentication because the default-enabled API is authenticated with hardcoded credentials that are identical across all installations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.