Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-57811: Realtyna Organic IDX Plugin Allows Remote Code Execution

CVE-2026-57811 CVE-2026-57811
Summary

The Realtyna Organic IDX plugin, used for real estate listings, has a security flaw that could allow hackers to inject and execute malicious code on a website. This could lead to unauthorized access and data theft. Update the plugin to the latest version (5.2.1 or higher) to fix the issue.

What to do
  • Update realtyna realtyna organic idx plugin to version 5.3.0.
Affected software
VendorProductAffected versions
realtyna realtyna organic idx plugin <= 5.2.0
Fix: upgrade to 5.3.0
Original title
Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This issue affects Real...
Original description
Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This issue affects Realtyna Organic IDX plugin: from n/a through <= 5.2.0.
nvd CVSS3.1 10.0
Vulnerability type
CWE-94 Code Injection
Published: 13 Jul 2026 · Updated: 17 Jul 2026 · First seen: 13 Jul 2026