
Exploits CVE-2026-57811, an unauthenticated RCE in Realtyna Organic IDX + WPL Real Estate WordPress plugin, enabling shell upload and command execution with mass scanning and multi-threading.
Critical Unauthenticated Remote Code Execution (CVSS 10.0) — Realtyna Organic IDX + WPL Real Estate ≤ 5.2.0
This tool exploits CVE-2026-57811, a critical vulnerability in the Realtyna Organic IDX + WPL Real Estate WordPress plugin that allows unauthenticated attackers to upload a malicious web shell via a deprecated mobile API endpoint and execute arbitrary system commands as the web server user.
| Property | Value |
|---|
| CVE ID | CVE-2026-57811 |
| CVSS Score | 10.0 (Critical) |
| CWE | CWE-94 — Code Injection |
| Affected Product | Realtyna Organic IDX + WPL Real Estate |
| Versions | ≤ 5.2.0 |
| Patched Version | 5.2.1 |
| Auth Required | TIDAK (unauthenticated) |
| Attack Vector | Network-based (remote) |
| Status | Actively Exploited |
The vulnerability exists in a deprecated mobile API endpoint with insufficient validation on the commands_directory parameter and file upload handling. An unauthenticated attacker can:
?wplview=io&wplformat=io)set_property command-u)-f targets.txt)-t 10) — fast parallel processingshells.txt with all shell URLs--payload-url)--delay)--proxy)# Clone the repository
git clone https://github.com/0xCyp1337/CVE-2026-57811.git
cd CVE-2026-57811
python3 CVE-2026-57811.py -h
# Install dependencies
pip install requests