Impact
The vulnerability is an improper control of filenames used in PHP include/require statements, allowing a local file to be included by the WordPress Tonda theme. This flaw can lead to the execution of arbitrary code or unauthorized disclosure of sensitive files on the server. The weak point is classified as CWE‑98, and the impact is a local file inclusion that could potentially be leveraged to gain elevated privileges or inject malicious code into the site.
Affected Systems
The Select‑Themes Tonda theme is affected in every release up through version 2.5. Users running any Tonda theme version 2.5 or older are at risk, regardless of the specific WordPress installation or server configuration.
Risk and Exploitability
The CVSS score of 7.5 places the flaw in the high severity range, but the EPSS score of less than 1 % indicates a very low likelihood that it has been exploited so far. The vulnerability is not listed in the CISA KEV catalog, and there is no widespread exploitation. Successful exploitation likely requires an attacker to have some level of direct or indirect access to invoke the theme’s file inclusion logic, suggesting a local or server‑side attack vector rather than purely remote.
OpenCVE Enrichment