CVE-2026-78261: WordPress Realtyna Organic IDX plugin plugin <= 5.4.1 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Realtyna Organic IDX pluginto a version that resolves this vulnerability.Fixed in 5.4.2
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or plugin-level privileges. Exploitation still requires user interaction, as indicated by the UI:R vector.
Which installations are affected?
Realtyna Organic IDX plugin versions 5.4.1 and earlier are affected according to the available information.
What is the likely impact of successful exploitation?
Successful cross-site scripting can affect confidentiality, integrity, and availability at low impact levels. The CVSS vector also indicates that the impact can extend beyond the vulnerable component's security scope.