Junglewise Threat Intelligence

CVE-2026-28152: Tonda Core Local File Inclusion

CVE-2026-28152 · Severity: high · CVSS 8.1 · Published 2026-08-24

Executive brief

Tonda Core is a WordPress plugin used to extend website functionality. Versions before 2.6 contain a local file inclusion vulnerability that allows attackers to read sensitive files from the web server without authentication, potentially exposing database credentials, configuration data, or other confidential information that could lead to account takeover or site compromise.

Technical details

This is a local file inclusion (LFI) vulnerability in Tonda Core WordPress plugin versions before 2.6. The vulnerability is unauthenticated, meaning no login credentials are required to exploit it. An attacker can craft requests to make the plugin load and expose server files that should not be publicly accessible. This allows reading sensitive files such as wp-config.php (containing database credentials), .env files, or other configuration files. The vulnerability has been patched in version 2.6 and later.

Affected products

  • Tonda Tonda Core < 2.6

Timeline

  • 2026-08-20: disclosed: Vulnerability reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
  • 2026-08-20: patched: Fix available in version 2.6

References