Skip to content

Realtyna vulnerabilities

3 CVEs tracked

In our reports, Realtyna appears in the context of critical Arbitrary File Upload vulnerabilities within its Organic IDX and WPL Real Estate plugins for WordPress. The main theme is the lack of file type validation in versions before 5.3.0, combined in some cases with default-enabled APIs authenticated via hardcoded credentials shipped across instances. The vulnerabilities tracked as CVE-2026-13714, CVE-2026-14483, and CVE-2026-16236 allow unauthenticated file uploads that could lead to remote code execution. Defenders should immediately update these plugins to the latest version, restrict access to functions like `saveLiveImages()`, and consult the vendor regarding the hardcoded credentials to mitigate the risk.

Azərbaycanca: Hesabatlarımızda Realtyna, xüsusilə WordPress üçün Organic IDX və WPL Real Estate plaginlərində kritik ixtiyari fayl yükləmə (Arbitrary File Upload) zəiflikləri ilə diqqət çəkir. Əsas mövzu 5.3.0 versiyasından əvvəlki bu plaginlərdə fayl tipi validasiyasının olmaması və bəzi hallarda standart olaraq aktiv olan, sərt kodlaşdırılmış etimadnamələrlə qorunan API-lərin mövcudluğudur. CVE-2026-13714, CVE-2026-14483 və CVE-2026-16236 kodlu zəifliklər uzaqdan kod icrasına səbəb ola biləcək icazəsiz fayl yükləmələrinə imkan verir. Müdafiəçilər bu plaginləri dərhal son versiyaya yeniləməli, `saveLiveImages()` kimi funksiyalara girişi məhdudlaşdırmalı və sərt kodlaşdırılmış etimadnamələrin dəyişdirilməsi üçün vendorla əlaqə saxlamalıdırlar.

This vendor's CVEs3

This hub is built from skopnix's own reporting on Realtyna: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.