What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Realtyna Realtyna Organic IDX plugin allows Code Injection.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.13.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Realtyna Realtyna Organic IDX plugin allows Code Injection.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.13.
Explanation of Vulnerability in Simple Terms
The Realtyna Organic IDX plugin through version 4.14.13 does not properly validate file uploads, allowing authenticated administrators to upload arbitrary files to the server. An attacker with admin credentials can upload malicious files—such as PHP scripts—to execute code on the site. This vulnerability affects the entire site and any data it hosts.
What an attacker can do
Upload and execute arbitrary files (such as PHP scripts) on the server to run their own code.
Potential impact on your site
A compromised admin account can lead to full site takeover, data theft, malware installation, and defacement.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site.
Key dates
External resources
Related vulnerabilities