CVE-2026-91014 PUBLISHED

Realtyna Organic IDX plugin + WPL Real Estate < 5.4.2 - Reflected XSS via Location Selector Endpoint

Assigner: WPScan
Reserved: 14.09.2026 Published: 17.09.2026 Updated: 17.09.2026

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run arbitrary web scripts in a visitor's browser if they can trick the visitor into following a crafted link (reflected XSS).

Product Status

Vendor Unknown
Product Realtyna Organic IDX plugin + WPL Real Estate
Versions Default: unaffected
  • affected from 0 to 5.4.2 (excl.)

Credits

  • Artus KG finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE