Junglewise Threat Intelligence

CVE-2026-65477: Select-Themes Tonda Core local file inclusion in WordPress plugin

CVE-2026-65477 · Severity: high · CVSS 7.5 · Published 2026-07-23

Vendors: Select-Themes.

Executive brief

Tonda Core, a WordPress plugin, contains a security flaw that allows users with 'Contributor' level access to view sensitive files on the web server. An attacker could use this to steal database credentials or other configuration details, potentially leading to a full takeover of the website. No official patch has been released, so administrators should monitor for unauthorized file access or consider alternative solutions.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Tonda Core plugin for WordPress (versions 2.1.2 and below) due to improper control of filenames in PHP include/require statements (CWE-98). The vulnerability requires 'Contributor' level authentication and is characterized by a high complexity (AC:H) according to the CVSS vector. An attacker can exploit this to include and execute local files on the server, potentially leading to the disclosure of sensitive information like wp-config.php or remote code execution if combined with other techniques. As of the advisory date, no official patch is available.

Affected products

  • Select-Themes Tonda Core <= 2.1.2

Timeline

  • 2026-01-20: other: Reported by researcher João Pedro S Alcântara (Kinorth)
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: NVD publication date

References