Description
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run arbitrary web scripts in a visitor's browser if they can trick the visitor into following a crafted link (reflected XSS).
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Reflected XSS allows arbitrary client‑side script execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises because the Realtyna Organic IDX and WPL Real Estate plugins mirror data from the location selector endpoint directly into the web page without sanitising or escaping it, constituting a reflected XSS (CWE‑79) flaw. An unauthenticated attacker can build a specially crafted URL that embeds malicious JavaScript, and if a site visitor clicks that URL the script runs in their browser. Because the flaw does not grant server‑side code execution or privilege escalation, the impact is confined to the victim’s session; however, it can be used to steal cookies, hijack the user’s session, perform phishing, or otherwise manipulate the client side.

Affected Systems

All installations of the Realtyna Organic IDX or WPL Real Estate WordPress plugins running a version earlier than 5.4.2 are affected. The flaw exists in the location selector endpoint present in any pre‑5.4.2 release of the plugin stack.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high severity vulnerability, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. The flaw is not listed in the CISA KEV catalog. Attackers must construct a malicious URL and lure a visitor to click it—a typical reflected XSS attack that relies on social engineering. Successful exploitation can lead to compromise of user sessions, theft of credentials, or delivery of phishing content. While the server itself remains uncompromised, the risk to a site hosting a large or valuable user base is that a single crafted link could affect many visitors.

Generated by OpenCVE AI on September 18, 2026 at 05:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Realtyna Organic IDX and WPL Real Estate plugins to version 5.4.2 or later to eliminate the vulnerable endpoint.
  • Configure a web application firewall or server‑side rule to block or sanitize requests to the location selector endpoint that contain untrusted query parameters.
  • If an update is not yet available, temporarily disable the location selector feature until the plugin is patched.

Generated by OpenCVE AI on September 18, 2026 at 05:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run arbitrary web scripts in a visitor's browser if they can trick the visitor into following a crafted link (reflected XSS).
Title Realtyna Organic IDX plugin + WPL Real Estate < 5.4.2 - Reflected XSS via Location Selector Endpoint
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:25:53.144Z

Reserved: 2026-09-14T16:39:57.416Z

Link: CVE-2026-91014

cve-icon Vulnrichment

Updated: 2026-09-17T12:09:24.598Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T06:16:52.977

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-91014

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:00:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')