CVE-2026-91014: Schwachstellen-Eintrag (NVD)
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run arbitrary web scripts in a visitor's browser if they can trick the visitor into following a crafted link (reflected XSS).
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-16 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-91014 | Realtyna Organic IDX Plugin/WPL Real Estate Plugin up to 5.4.1 on WordPress cross site scripting (EUVD-2026-81355)
A vulnerability labeled as problematic has been found in Realtyna Organic IDX Plugin and WPL Real Estate Plugin up to 5.4.1 on WordPress. This vulnerability affects unknown code. The manipulation results in cross site scripting. This vulner