Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-14483— Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command

Quick assessment

Affected
realtyna Realtyna Organic IDX plugin + WPL Real Estate
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 平台上的 Realtyna Organic IDX 插件与 WPL Real Estate 插件在所有不超过 5.2.0 版本的系统中均存在任意文件上传漏洞。该漏洞源于上传功能中缺失对文件类型的校验,同时结合了一个通过静态的、由插件预置的 API 凭据进行认证的公开可访问 I/O 端点,且这些凭据在所有安装实例中均相同。这使得未授权的攻击者能够上传可能可执行的文件,从而可能导致远程代码执行。WPL I/O 服务端点注册在 WordPress 公共初始化钩子上,未进行任何 WordPress 权限

CVSS 9.8 · Critical EPSS 3.97% · P90

Public Exploits 1

Affected Version Matrix 1

VendorProduct Version RangeStatus
realtyna Realtyna Organic IDX plugin + WPL Real Estate ≤ 5.2.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-14483

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command
Source: CVE Program / CVE List V5
Vulnerability Description
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by static, plugin-seeded API credentials that are identical across all installations. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The WPL I/O service endpoint is registered on the public WordPress init hook with no WordPress capability check, and the required api_key and api_secret values are static defaults seeded by the plugin's own SQL migration files, meaning any unauthenticated attacker who knows these publicly documented defaults can reach and exploit the vulnerable upload path.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
危险类型文件的不加限制上传
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
realtyna Realtyna Organic IDX plugin + WPL Real Estate 0 ~ 5.2.0 -

II. Public POCs for CVE-2026-14483

# POC Description Source Link Shenlong Link
1 Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress <= 5.2.0 contains an unrestricted file upload vulnerability caused by missing file type validation and static API credentials, letting unauthenticated attackers upload executable files and achieve remote code execution, exploit requires knowledge of static API credentials. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-14483.yaml POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-14483

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-14483 (2)

Vendor Advisories for CVE-2026-14483 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-14483

No comments yet


Leave a comment