Impact
A known Local File Inclusion flaw resides in the Tonda Core plugin for WordPress, affecting all releases up to and including 2.1.2. The vulnerability can allow a contributor user to cause the plugin to read arbitrary local files. This could lead to leakage of sensitive data, potential compromise of configuration files, or the execution of additional exploits in environments where the site runs with elevated privileges. The weakness is classified under CWE‑98, which highlights missing or insufficient protection against local file access.
Affected Systems
The attack impacts WordPress sites that have the Select‑Themes Tonda Core plugin installed with a version number of 2.1.2 or earlier. No other vendors or product versions are identified as affected in the current data.
Risk and Exploitability
The CVSS score of 7.5 denotes a high severity risk, and the EPSS score of less than 1% suggests that exploitation is unlikely but possible. The vulnerability is not listed in the CISA KEV catalog, indicating that no widespread exploits are recorded to date. The attack vector requires a user with contributor role or similar permission; an attacker would need to authenticate to the WordPress back‑end, then trigger the LFI through a vulnerable plugin function. If the attacker succeeds, they may read local files but would have limited scope to the web server's file system and the site's user permissions.
OpenCVE Enrichment