CVE-2026-14483 is a critical unauthenticated arbitrary file upload vulnerability affecting the Realtyna Organic IDX plugin together with the WPL Real Estate plugin for WordPress in all versions up to and including 5.2.0. The flaw is caused by missing file type validation in the plugin's upload function and by exposure of a public WPL I/O service endpoint that is reachable without a WordPress capability check. The endpoint is registered on the public WordPress init hook and relies only on static API credentials seeded by the plugin's SQL migration files, with identical default values across installations. As a result, an unauthenticated attacker who knows the default credentials can access the vulnerable upload path and submit files of dangerous types, including potentially executable content. This can enable remote code execution on the affected WordPress host.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit for CVE-2026-14483 and contains two files: a README describing the vulnerability and usage, and a single Python entry point, exploit.py. The exploit targets the Realtyna WPL / Organic IDX WordPress plugin (real-estate-listing-realtyna-wpl <= 5.2.0), abusing a publicly reachable I/O service exposed through the WordPress site root. It authenticates to that service using static hard-coded default keys that are identical across installations, then invokes the set_property command in the mobile_application command directory to upload an attacker-supplied file via multipart form data. The exploit’s main capability is unauthenticated remote code execution through arbitrary file upload. It uploads a PHP webshell whose filename is prefixed with image_ to satisfy the plugin’s expected naming behavior, relying on the vulnerable code to strip the prefix and save the file without extension or MIME validation. After upload, the script does not receive the created property ID directly, so it enumerates likely property directories under wp-content/uploads/WPL/1..80 until it finds the uploaded shell by issuing a benign echo marker command. Once located, it can either execute a single arbitrary command through the c GET parameter or trigger a bash reverse shell to an operator-supplied host and port. Structurally, exploit.py is straightforward: _get() performs HTTP GET requests and handles errors; upload() builds the vulnerable POST request with the required query parameters and multipart body; find_shell() brute-forces the upload directory path and validates shell execution using a marker string; main() parses arguments, generates a timestamp-based PHP filename, uploads the shell, locates it, and either runs a command or launches a reverse shell. The code uses only Python standard library modules (argparse, sys, time, urllib.*), making it dependency-free and easy to run. This is a real exploit rather than a detector, and because it includes a working webshell payload and reverse-shell option, it is best classified as OPERATIONAL.
This repository contains a single Python exploit script and a README. The exploit targets CVE-2026-14483 in the Realtyna WPL Real Estate Listing WordPress plugin and is designed for mass exploitation against multiple base URLs using concurrent threads. The script structure includes banner/output helpers, a WPLExploit class for single-target exploitation, and a MassExploit workflow that loads targets from a file and processes them in parallel. Core capability: unauthenticated RCE via webshell upload. The exploit first fingerprints the plugin version by requesting plugin files under /wp-content/plugins/real-estate-listing-realtyna-wpl/, preferring readme.txt and falling back to wpl.php. It then retrieves exposed API credentials from a public SQL migration dump, uses those credentials to call the WPL I/O API action set_property, and uploads a PHP payload disguised as an image. Finally, it brute-forces property IDs up to a configurable maximum to locate the uploaded shell under /wp-content/uploads/WPL/{id}/0x89MADEXPLOITS.php. The default payload is an embedded PHP upload shell that prints the marker MADEXPLOITS and provides a form-based arbitrary file upload capability, making the exploit more than a simple proof of concept. The script supports custom payloads, configurable user ID ownership, timeout, thread count, debug logging, and a --force option to bypass the version gate. Overall, this is a real exploit, not merely a detector, and it is operational but not framework-based.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated file upload vulnerability in the WPL WordPress component/plugin.
A critical unauthenticated arbitrary file upload vulnerability in the Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress (through version 5.2.0) caused by missing file type validation and publicly accessible static API credentials, enabling possible remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.