logo

Critical Code Injection Vulnerability in Realtyna Organic IDX Plugin Disclosed

ID: b423cf8d-26b7-521c-8eab-93836247f54e

STIX ID: report--b423cf8d-26b7-521c-8eab-93836247f54e

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-07-14

Date Updated: 2026-07-17

...
...

A critical unauthenticated code injection vulnerability (CVE-2026-57811, CVSS 10.0) has been disclosed in the Realtyna Organic IDX WordPress plugin affecting all versions up to 5.2.0, enabling remote code execution and potential full system compromise; there are currently no vendor advisories or patches and no known exploits in the wild, so users are advised to disable or remove the plugin until a fix is issued.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.