Impact
Unauthenticated Local File Inclusion in Tonda Core versions older than 2.6 allows an attacker to read local files within the WordPress installation, potentially exposing sensitive configuration data and enabling further exploitation. The flaw is identified as CWE‑98 and does not require user authentication to be triggered.
Affected Systems
All WordPress sites running the Select‑Themes Tonda Core plugin with a version earlier than 2.6 are vulnerable. Users must verify their plugin version and ensure no legacy copies remain installed.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity vulnerability. No EPSS score is currently available, and the flaw is not listed in CISA’s KEV catalogue, suggesting limited public exploitation yet a significant risk if left unapplied. The likely attack vector is a web‑based request that exploits directory traversal or malformed parameters to include sensitive files, requiring no elevated privileges on the host.
OpenCVE Enrichment