SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-13714

CRITICAL · CVSS 9.8 EPSS 0.72% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The Realtyna Organic IDX and WPL Real Estate plugins for WordPress prior to version 5.3.0 are vulnerable due to inadequate validation of uploaded files, allowing unauthenticated attackers to exploit a default-enabled API secured by hardcoded credentials. This critical vulnerability enables the execution of arbitrary PHP code, potentially compromising the entire WordPress site. WordPress site administrators using these plugins should prioritize immediate updates to mitigate the risk of remote code execution.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-13714
Severity
CRITICAL
CVSS
9.8
EPSS
0.72%
WordPress

Original NVD Description

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.