A critical code injection vulnerability (CVE-2026-57811) has been disclosed in the Realtyna Organic IDX plugin for WordPress. The flaw, rated CVSS 10.0, stems from improper validation of user-supplied input in the 'real-estate-listing-realtyna-wpl' component, enabling attackers to execute arbitrary code via malicious payloads. This vulnerability affects all versions of the plugin through 5.2.0. WordPress sites utilizing the plugin are at risk of remote code execution, potential data exfiltration, and server compromise. Immediate remediation is required: administrators should upgrade to a patched version provided by the vendor. Until updated, restrict access to affected endpoints and monitor server logs for suspicious activity. The high severity score indicates a critical risk requiring urgent attention. No evidence of active exploitation has been reported, but the vulnerability's remote exploitability and high impact potential necessitate proactive mitigation.
CRITICAL
CVSS 10.0
CVE-2026-57811
2026-08-12
Critical Code Injection Vulnerability in Realtyna Organic IDX Plugin (CVE-2026-57811)
A critical code injection vulnerability in Realtyna Organic IDX plugin for WordPress allows remote code inclusion. CVSS 10.0. Affects versions through 5.2.0. Immediate patching required to mitigate exploitation risks.