Realtyna Organic IDX plugin + WPL Real Estate < 5.4.2 - Reflected XSS via Location Selector Endpoint
Summary
| CVE | CVE-2026-91014 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 06:16:52 UTC |
| Updated | 2026-09-17 06:16:52 UTC |
| Description | The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run arbitrary web scripts in a visitor's browser if they can trick the visitor into following a crafted link (reflected XSS). |
Risk And Classification
Problem Types: CWE-79 Cross-Site Scripting (XSS)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | Realtyna Organic IDX Plugin WPL Real Estate | affected 5.4.2 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/a57a9fbd-6f77-463f-a9fa-79503c12a49c | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Artus KG (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.