---
id: CVE-2026-91014
title: >-
  The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before
  5.4.2 does not sanitise and escape some of its parameters before reflecting
  them back in the page, allowing unauthenticated attackers to run arbitrary web
  scripts …
summary: >-
  The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before
  5.4.2 does not sanitise and escape some of its parameters before reflecting
  them back in the page, allowing unauthenticated attackers to run arbitrary web
  scripts …
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'
cwe:
  - CWE-79
product: Realtyna Organic IDX plugin + WPL Real Estate
affected:
  - realtyna_organic_idx_plugin_+_wpl_real_estate < 5.4.2
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:32.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91014'
references:
  - url: 'https://wpscan.com/vulnerability/a57a9fbd-6f77-463f-a9fa-79503c12a49c/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00164
epssPercentile: 0.05991
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T12:10:34.959534Z'
ingestedAt: '2026-09-17T06:12:17.973Z'
---

## Overview

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run arbitrary web scripts in a visitor's browser if they can trick the visitor into following a crafted link (reflected XSS).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
