Impact
The Tonda theme for WordPress before version 2.6 contains an unauthenticated Local File Inclusion flaw. An attacker can manipulate request parameters to read files outside the intended directory. Depending on the included file, this may expose confidential data such as configuration files or credentials, and if the file is interpreted as PHP it can lead to remote code execution. The weakness stems from insufficient input validation, corresponding to CWE‑98.
Affected Systems
The vulnerability affects sites that have installed the WordPress Tonda theme from the Select‑Themes team with a version older than 2.6. It is confined to the theme itself and does not directly impact the core WordPress platform or other plugins.
Risk and Exploitability
The flaw is rated with a CVSS score of 8.1, indicating high severity. The EPSS score is not available, so the current exploitation probability is unknown, and it is not listed in CISA’s KEV catalog. Attackers can reach the vulnerable code without authentication through ordinary HTTP requests, making it readily exploitable. Because Local File Inclusion can lead to arbitrary file reads and potentially remote code execution, the operational impact for affected servers can be significant.
OpenCVE Enrichment