A vulnerability was found in Realtyna Organic IDX Plugin and WPL Real Estate Plugin up to 5.2.x on WordPress. It has been classified as critical. The affected element is an unknown function. Performing a manipulation results in unrestricted upload.
This vulnerability is reported as CVE-2026-13714. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.