CVE-2026-13714

CRITICAL

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-13714. PoCs published by incogbyte.

AI-analyzed exploit summary This exploit targets an unauthenticated arbitrary file upload vulnerability in the Realtyna Organic IDX Plugin + WPL Real Estate (versions <= 5.2.0). The flaw stems from hardcoded default API keys and a deprecated mobile_application add-on's set_property command, which lacks validation and allows unrestricted PHP file uploads to achieve remote code execution.

Description

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.

Exploits (1)

github WORKING POC 5 stars
by incogbyte · pythonpoc
https://github.com/incogbyte/wp-cve-exploits/tree/main/CVE-2026-13714

This exploit targets an unauthenticated arbitrary file upload vulnerability in the Realtyna Organic IDX Plugin + WPL Real Estate (versions <= 5.2.0). The flaw stems from hardcoded default API keys and a deprecated mobile_application add-on's set_property command, which lacks validation and allows unrestricted PHP file uploads to achieve remote code execution.

Classification
Working Poc 99%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Realtyna Organic IDX Plugin + WPL Real Estate <= 5.2.0 (WordPress plugin)
No auth needed
Prerequisites: Target must be running a vulnerable version (<= 5.2.0) of the plugin · Default hardcoded API keys must not have been changed · The deprecated mobile_application add-on must be present (default in vulnerable versions)
mistral-large-3 · analyzed Jul 30, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/69f9dcd8-ab3c-46ed-ac6b-2f1db35f8d1f/

Scores

CVSS v3 9.8
EPSS 0.0046
EPSS Percentile 37.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
None/Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0
Published Jul 27, 2026
Tracked Since Jul 27, 2026