{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/wpl-real-estate/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-13714"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WPL Real Estate","Organic IDX"],"_cs_severities":["critical"],"_cs_tags":["wordpress","rce","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Realtyna"],"content_html":"\u003cp\u003eCVE-2026-13714 is a critical vulnerability (CVSS 9.8) affecting Realtyna's Organic IDX and WPL Real Estate plugins for WordPress versions prior to 5.3.0. The vulnerability resides in the plugin's I/O API, which fails to perform server-side file type validation. This flaw allows unauthenticated attackers to upload arbitrary files, including PHP shells, to the server. Publicly available exploit code demonstrates that attackers can leverage default API keys to bypass authentication and execute code. The exploit supports automated fingerprinting of WordPress installations, brute-force identification of the upload path, and multipart form-data requests to upload malicious files. Defenders should prioritize patching and monitoring for unauthorized file uploads in the plugin's upload directory.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker sends a probe request to \u003ccode\u003e?get_realtyna_platform=1\u003c/code\u003e to fingerprint the target and confirm the presence of the vulnerable WPL Real Estate plugin.\u003c/li\u003e\n\u003cli\u003eAttacker uses default, hardcoded I/O API keys to authenticate against the plugin's endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a multipart/form-data POST request targeting the \u003ccode\u003eset_property\u003c/code\u003e command.\u003c/li\u003e\n\u003cli\u003eAttacker embeds a PHP web shell (e.g., \u003ccode\u003eimage_Nx_abc.php\u003c/code\u003e) within the \u003ccode\u003efile[]\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eThe plugin saves the file to the \u003ccode\u003ewp-content/uploads/WPL/{pid}/\u003c/code\u003e directory without validating the file extension or content.\u003c/li\u003e\n\u003cli\u003eAttacker brute-forces the PID (Property ID) directory structure to locate the exact path of the uploaded file.\u003c/li\u003e\n\u003cli\u003eAttacker sends a GET request to the discovered file path in \u003ccode\u003ewp-content/uploads/WPL/{pid}/Nx_*\u003c/code\u003e to trigger PHP execution.\u003c/li\u003e\n\u003cli\u003eAttacker gains persistent remote code execution on the WordPress host.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full site compromise, allowing attackers to exfiltrate sensitive database information, modify site content, or use the server for further lateral movement within the hosting environment. Given the widespread use of the WPL Real Estate plugin for property management, the risk of data exposure for real estate firms and their clients is significant.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate WPL Real Estate and Organic IDX plugins to version 5.3.0 or later immediately.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to detect web requests attempting to access or write to the vulnerable plugin's upload directory.\u003c/li\u003e\n\u003cli\u003eRotate the I/O API keys in the \u003ccode\u003ewpl_settings\u003c/code\u003e table to invalidate currently known default keys.\u003c/li\u003e\n\u003cli\u003eImplement a rewrite rule or server configuration to block direct access to \u003ccode\u003ewp-content/uploads/WPL/\u003c/code\u003e files ending in \u003ccode\u003e.php\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eDisable the I/O API via plugin settings if it is not required for daily business operations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-02T19:59:10Z","date_published":"2026-08-02T19:59:10Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-13714/","summary":"A critical unauthenticated remote code execution vulnerability, CVE-2026-13714, in Realtyna WPL Real Estate and Organic IDX plugins allows attackers to upload arbitrary PHP shells via the I/O API.","title":"Critical Unauthenticated RCE in Realtyna WPL Real Estate Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-13714/"}],"language":"en","title":"CraftedSignal Threat Feed - WPL Real Estate","version":"https://jsonfeed.org/version/1.1"}