CVE-2026-13714 is an unrestricted file upload vulnerability in the Realtyna Organic IDX + WPL Real Estate WordPress plugin before version 5.3.0. The plugin does not properly validate uploaded file types, and its upload capability is exposed through an API that is enabled by default and protected only by hardcoded credentials that are identical across installations. Because the API can be accessed without per-instance secret material and the upload mechanism accepts arbitrary files, an unauthenticated attacker can upload a PHP payload and execute it on the target server, resulting in remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit PoC consisting of one Python script and a README. The main file, `CVE-2026-13714.py`, targets CVE-2026-13714 in the Realtyna Organic IDX + WPL Real Estate WordPress plugin before version 5.3.0. The exploit abuses a vulnerable WPL I/O API that uses hardcoded credentials and permits unauthenticated file upload. Operational flow: the script creates a temporary PHP payload containing `system($_GET['c'])`, uploads it to the target WordPress site using an HTTP POST with specific WPL API query parameters (`wplview=io`, `wplformat=io`, `cmd=set_property`, `commands_directory=mobile_application`) and the hardcoded `public_key`/`private_key`, then iterates through likely upload paths and property IDs 1 through 24 to locate the deployed shell. Once found, it executes an operator-supplied command via the `c` GET parameter and prints the response. Capabilities: unauthenticated arbitrary file upload, webshell deployment, path discovery of uploaded payload, and arbitrary remote OS command execution over HTTP. The payload is basic but functional, making the exploit OPERATIONAL rather than a mere detection script or documentation-only repository. Repository structure is minimal: `CVE-2026-13714.py` is the executable entry point, while `README.md` documents affected versions, usage examples, reverse-shell ideas, detection guidance, and mitigation notes. No external framework is used.
This repository is a small standalone exploit package containing one Python exploit script, a README, and a license file. The main file, CVE-2026-13714.py, targets CVE-2026-13714 in Realtyna WPL Real Estate for WordPress. It exploits a built-in I/O API protected only by hardcoded public/private keys shared across installations, allowing unauthenticated multipart file upload via the set_property command. The script supports three modes: detection-only fingerprinting, canary upload of a benign .txt file, and active exploitation by uploading a PHP payload and verifying execution. The embedded payload is a simple PHP uploader that prints a fixed marker and can accept subsequent file uploads, effectively providing a web-accessible foothold and enabling remote code execution. The exploit uses Python stdlib networking with disabled TLS verification, randomized user agents, and multithreading via ThreadPoolExecutor for mass scanning. It appears to perform WordPress/WPL root discovery, fingerprinting using the get_realtyna_platform probe and HTML signatures, then brute-forces likely upload directories under wp-content/uploads/WPL or wp-content/uploads/wpl using a PID range to locate the uploaded file. Results are logged locally under Nx_hit/. Overall, this is a real, operational exploit rather than a mere detector: it automates unauthenticated upload and post-upload verification against vulnerable WPL installations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.