CVE-2026-28151: WordPress Tonda theme < 2.6 - Local File Inclusion vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated Local File Inclusion in Tonda < 2.6 versions.
Affected Software
1 affected component
WordPress Tonda theme<2.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Tonda Themeto a version that resolves this vulnerability.Fixed in 2.6
Event History
Aug 24, 2026
CVE Published
via MITRE·11:54 AM
Data Sourced
via MITRE·11:54 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is described as unauthenticated, so an attacker does not need a WordPress account or other prior privileges. Exploitation is network-accessible, although the high attack-complexity rating indicates additional conditions are required.
2
Which installations are affected?
WordPress sites using the Tonda theme at versions earlier than 2.6 are affected. The provided data does not identify any configuration prerequisite.
3
What is the immediate remediation?
Update the Tonda theme to version 2.6 or later. The provided data does not specify a workaround or mitigation for sites that cannot update immediately.