Realtyna Organic IDX Plugin Cross-Site Request Forgery Vulnerability Allowing Local File Inclusion
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Realtyna Organic IDX plugin for WordPress, affecting versions through 5.0.0. This vulnerability allows for PHP Local File Inclusion, which could enable a malicious actor to include local files from the target website and display their contents, potentially leading to a complete database takeover depending on the configuration.
Impact
Exploitation of this vulnerability could result in Local File Inclusion, allowing attackers to read sensitive files on the server, such as those containing database credentials, which could lead to a full database takeover.
Remediation
Users of the Realtyna Organic IDX plugin should update to version 5.0.1 or later. Patchstack users can enable auto-updates for vulnerable plugins.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
