CVE-2026-14483

Published: Lug 31, 2026 Last Modified: Lug 31, 2026
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,8
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by static, plugin-seeded API credentials that are identical across all installations. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The WPL I/O service endpoint is registered on the public WordPress init hook with no WordPress capability check, and the required api_key and api_secret values are static defaults seeded by the plugin's own SQL migration files, meaning any unauthenticated attacker who knows these publicly documented defaults can reach and exploit the vulnerable upload path.

434

Unrestricted Upload of File with Dangerous Type

Draft
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability
Potential Impacts:
Execute Unauthorized Code Or Commands
Applicable Platforms
Languages: ASP.NET, PHP, Not Language-Specific
Technologies: Web Server, AI/ML
View CWE Details
https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/tru…
https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/tru…
https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/tru…
https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/tru…
https://plugins.trac.wordpress.org/browser/real-estate-listing-realtyna-wpl/tru…
https://www.wordfence.com/threat-intel/vulnerabilities/id/23068a98-623d-4eb3-a7…