WordPress Realtyna Organic IDX plugin + WPL Real Estate是WordPress基金会开源的一款房地产列表插件。 WordPress Realtyna Organic IDX plugin + WPL Real Estate 5.3.0之前版本存在任意文件上传漏洞,该漏洞源于未验证上传文件类型,且文件上传功能仅由默认启用的API和硬编码凭据保护,可能导致未认证攻击者上传任意PHP文件并实现远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Realtyna Organic IDX plugin + WPL Real Estate | < 5.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Realtyna Organic IDX plugin + WPL Real Estate | 0 ~ 5.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14190 | Sina Extension for Elementor < 3.10.2 - Reflected XSS | |
| CVE-2026-14820 | Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via | |
| CVE-2026-14827 | Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter | |
| CVE-2026-9830 | BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering v | |
| CVE-2026-14203 | Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title | |
| CVE-2026-14568 | WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion | |
| CVE-2026-14236 | Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect | |
| CVE-2026-14289 | WP FacturaONE < 5.37 - Unauthenticated Remote Code Execution | |
| CVE-2026-14235 | WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Do | |
| CVE-2026-13597 | QRcode Login for WeChat <= 1.3 - Unauthenticated Account Takeover | |
| CVE-2026-13726 | Multiple Page Generator Plugin – MPG < 4.1.8 - Reflected XSS via mpg_shortcode | |
| CVE-2026-10082 | Advanced Ads – Ad Manager & AdSense < 2.0.23 - Contributor+ Stored XSS via the_ad Shortcod | |
| CVE-2026-14189 | WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields | |
| CVE-2026-13400 | Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer | |
| CVE-2026-13332 | Masteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (Denial of Serv | |
| CVE-2026-13390 | The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulati | |
| CVE-2026-13152 | Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escal | |
| CVE-2026-12982 | Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery | |
| CVE-2026-12255 | MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordles | |
| CVE-2026-12394 | MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet