Impact
The flaw is an improper control of code generation that allows an attacker to inject and execute arbitrary code within the WordPress environment. The identified weakness corresponds to CWE‑94, code injection, and can give an attacker full control over the affected site, compromising confidentiality, integrity, and availability.
Affected Systems
This issue affects the Realtyna Organic IDX plugin for WordPress, versions from the earliest available up to and including 5.2.0; all installations running or earlier than 5.2.0 are potentially at risk.
Risk and Exploitability
The CVSS score of 10 identifies this vulnerability as critical, although the EPSS score is reported as <1%—indicating a very low but non‑zero probability of exploitation. The flaw is not listed in CISA KEV. The likely attack vector is a remote request that can trigger code inclusion, most probably requiring the ability to send a crafted request to the plugin’s interfaces. Successful exploitation could lead to complete system compromise.
OpenCVE Enrichment