Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This issue affects Realtyna Organic IDX plugin: from n/a through <= 5.2.0.
Published: 2026-07-13
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper control of code generation that allows an attacker to inject and execute arbitrary code within the WordPress environment. The identified weakness corresponds to CWE‑94, code injection, and can give an attacker full control over the affected site, compromising confidentiality, integrity, and availability.

Affected Systems

This issue affects the Realtyna Organic IDX plugin for WordPress, versions from the earliest available up to and including 5.2.0; all installations running or earlier than 5.2.0 are potentially at risk.

Risk and Exploitability

The CVSS score of 10 identifies this vulnerability as critical, although the EPSS score is reported as <1%—indicating a very low but non‑zero probability of exploitation. The flaw is not listed in CISA KEV. The likely attack vector is a remote request that can trigger code inclusion, most probably requiring the ability to send a crafted request to the plugin’s interfaces. Successful exploitation could lead to complete system compromise.

Generated by OpenCVE AI on August 1, 2026 at 10:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Realtyna Organic IDX plugin to a version newer than 5.2.0, which contains the fix for the code injection flaw.
  • If a newer version is unavailable, remove or undeploy the plugin entirely to eliminate the attack surface.
  • Disable the plugin’s code inclusion functionality or restrict access to administrative interfaces until a patch is applied.

Generated by OpenCVE AI on August 1, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Realtyna
Realtyna realtyna Organic Idx Plugin
Wordpress
Wordpress wordpress
Vendors & Products Realtyna
Realtyna realtyna Organic Idx Plugin
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This issue affects Realtyna Organic IDX plugin: from n/a through <= 5.2.0.
Title WordPress Realtyna Organic IDX plugin plugin <= 5.2.0 - Remote Code Execution (RCE) vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Realtyna Realtyna Organic Idx Plugin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:15:28.359Z

Reserved: 2026-06-25T08:05:16.223Z

Link: CVE-2026-57811

cve-icon Vulnrichment

Updated: 2026-07-13T13:15:25.666Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:30:04Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')