Impact
The vulnerability is a cross‑site request forgery (CSRF) flaw that allows an attacker to manipulate a legitimate user’s browser to trigger the plugin’s PHP local file inclusion logic. This could enable the attacker to read or execute arbitrary files on the server, potentially exposing sensitive configuration data or allowing remote code execution. The weakness is classified as CWE‑352 and is rated a high severity (CVSS 7.5).
Affected Systems
Realtyna Organic IDX plugin for WordPress versions up to and including 5.0.0 are impacted.
Risk and Exploitability
A high CVSS score of 7.5 and an extremely low EPSS (<1%) suggest the flaw is serious but not widely exploited currently, and it is not listed in the CISA KEV catalog. The likely attack vector is a CSRF attack where a malicious site tricks an authenticated user into submitting a crafted request that triggers the local file inclusion path. Successful exploitation would require the victim to be logged into the WordPress site with the plugin active. As the CVE does not list a broader exploitation scenario, the risk is confined to sites running the affected plugin version.
OpenCVE Enrichment
EUVD