Vendor
critical
advisory
Critical Unauthenticated RCE in Realtyna WPL Real Estate Plugin
1 rule 2 TTPs 1 CVE 1 IOCA critical unauthenticated remote code execution vulnerability, CVE-2026-13714, in Realtyna WPL Real Estate and Organic IDX plugins allows attackers to upload arbitrary PHP shells via the I/O API.
WPL Real Estate +1
wordpress
rce
vulnerability
1r
2t
1c
1i
high
advisory
Arbitrary File Upload Vulnerability in Realtyna Organic IDX Plugin
2 TTPs 1 CVEThe Realtyna Organic IDX plugin for WordPress contains an arbitrary file upload vulnerability (CVE-2026-16236) due to improper validation and authentication, allowing remote attackers to achieve remote code execution.
Organic IDX
2t
1c
critical
advisory
Unauthenticated Remote Code Execution in Realtyna Organic IDX and WPL Real Estate WordPress Plugins
1 rule 1 CVE 1 IOCThe Realtyna Organic IDX and WPL Real Estate plugins contain an arbitrary file upload vulnerability (CVE-2026-14483) allowing unauthenticated remote code execution via static, default API credentials.
PoC
Organic IDX plugin +2
wordpress
rce
file-upload
cve-2026-14483
1r
1c
1i
updated