What is CVE-2026-16236?
This is a critical Arbitrary File Upload vulnerability in the Realtyna Organic IDX plugin for WordPress, affecting versions up to and including 5.3.0. The flaw exists due to missing file type/extension validation in the saveLiveImages() function and insufficient authorization checks on the get_keys() AJAX handler, which could allow an unauthenticated attacker to upload malicious files and potentially achieve remote code execution. Updating the plugin to the latest patched version is strongly recommended.
Azərbaycanca: Bu, Realtyna Organic IDX pluqininin 5.3.0 və aşağı versiyalarında aşkarlanmış kritik 'Arbitrary File Upload' zəifliyidir. Zəiflik saveLiveImages() funksiyasında fayl tipi yoxlamasının olmaması və get_keys() AJAX idarəedicisindəki yetərsiz avtorizasiya səbəbindən yaranır. Bu, autentifikasiya olunmamış hücumçuya serverdə ixtiyari fayl yükləməyə imkan verir, saytın tam ələ keçirilməsinə səbəb ola bilər. Pluqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434; shared vendor: Realtyna
FAQ2
Which versions of the Realtyna Organic IDX plugin are affected by CVE-2026-16236?
This vulnerability affects all versions of the Realtyna Organic IDX plugin up to and including 5.3.0.
What can an unauthenticated attacker achieve by successfully exploiting CVE-2026-16236?
The attacker can upload arbitrary files to the server, potentially leading to complete site takeover.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.