CVE-2026-28152

8.1

Select-Themes · Tonda Core

The Tonda Core WordPress plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read or execute arbitrary files on the server.

Executive summary

An unauthenticated local file inclusion vulnerability in the Tonda Core WordPress plugin, rated 8.1 on the CVSS scale, creates a high risk of total system compromise.

Vulnerability

The plugin fails to sanitize user inputs used in include or require statements, enabling an unauthenticated attacker to include arbitrary files, which may lead to remote code execution.

Business impact

Successful exploitation of this vulnerability could allow an attacker to gain full control over the WordPress installation. This could result in complete data theft, site defacement, or the installation of persistent backdoors, significantly impacting organizational operations and customer trust.

Remediation

Immediate Action: Update the Tonda Core plugin to version 2.6 or higher immediately to address the file inclusion flaw.

Proactive Monitoring: Inspect server file integrity and monitor web access logs for suspicious requests containing directory traversal sequences or unexpected file inclusions.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block common local file inclusion attack patterns until the patch can be applied.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

Given the potential for complete system compromise, this vulnerability should be treated with extreme urgency. Administrators must update the Tonda Core plugin to the latest version immediately to eliminate the risk of unauthorized file access and remote code execution.

More Select-Themes CVEs