Realtyna Organic IDX Plugin Cross-Site Request Forgery Vulnerability Allowing Local File Inclusion

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Realtyna Organic IDX plugin for WordPress, affecting versions through 5.0.0. This vulnerability allows for PHP Local File Inclusion, which could enable a malicious actor to include local files from the target website and display their contents, potentially leading to a complete database takeover depending on the configuration.

Impact

Exploitation of this vulnerability could result in Local File Inclusion, allowing attackers to read sensitive files on the server, such as those containing database credentials, which could lead to a full database takeover.

Remediation

Users of the Realtyna Organic IDX plugin should update to version 5.0.1 or later. Patchstack users can enable auto-updates for vulnerable plugins.

Added: Aug 20, 2025, 8:24 AM
Updated: Aug 20, 2025, 8:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.4
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.