Impact
The vulnerability is an unauthenticated Cross‑Site Scripting flaw that permits attackers to inject arbitrary JavaScript into pages rendered by the plugin. Such scripts can steal session cookies, deface the site, or redirect visitors to malicious sites, compromising confidentiality and integrity of site users.
Affected Systems
WordPress Realtyna Organic IDX plugin, versions 5.4.1 and earlier, used within WordPress installations by the vendor Realtyna.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity for an XSS vulnerability. No EPSS score is reported, so exploitation probability remains unknown, and it is not listed in CISA KEV. Attackers can trigger the flaw by accessing plugin pages or submitting data through the plugin’s input fields without authentication, making the risk significant for any publicly accessible WordPress site that runs the affected plugin.
OpenCVE Enrichment