Junglewise Threat Intelligence

CVE-2026-28151: Tonda WordPress Theme local file inclusion

CVE-2026-28151 · Severity: high · CVSS 8.1 · Published 2026-08-24

Executive brief

Tonda is a WordPress theme used by thousands of websites to control their appearance and content. An unauthenticated attacker can exploit this vulnerability to read sensitive files from the server, potentially exposing database credentials, configuration files, or other confidential data. This could lead to complete website or account takeover.

Technical details

A local file inclusion (LFI) vulnerability exists in Tonda WordPress Theme versions below 2.6 that allows unauthenticated attackers to read arbitrary files from the server. The vulnerability is accessible without authentication and can be exploited remotely over the network. Successful exploitation enables attackers to access sensitive files such as wp-config.php, leading to credential exposure and potential system compromise. The vulnerability is patched in version 2.6 and later.

Affected products

  • Tonda Tonda < 2.6

Timeline

  • 2026-08-20: disclosed: Published by Patchstack
  • 2026-08-24: advisory: NVD entry published

References