logo

Critical Code Injection Vulnerability in Realtyna Organic IDX Plugin Disclosed

ID: 35ddb770-9af2-57bc-a1bd-1180267e83ee

STIX ID: report--35ddb770-9af2-57bc-a1bd-1180267e83ee

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-07-14

Date Updated: 2026-07-16

...
...

A critical code-injection vulnerability (CVE-2026-57811) has been disclosed in the Realtyna Organic IDX WordPress plugin affecting all versions up to 5.2.0 and allowing unauthenticated remote code execution; the flaw carries a CVSS score of 10.0, no public exploit or vendor patch has been reported as of 2026-07-13, and users are advised to disable or remove the plugin until a fix is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.