CVE-2026-28152: WordPress Tonda Core plugin < 2.6 - Local File Inclusion vulnerability
Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Tonda Core Pluginto a version that resolves this vulnerability.Fixed in 2.6
Event History
Frequently Asked Questions
Which installations should be treated as affected?
WordPress sites using Tonda Core versions earlier than 2.6 should be treated as affected. Confirm the installed Tonda Core version as part of triage.
Does an attacker need a WordPress account or user interaction to exploit this issue?
No. The vulnerability is rated with no privileges required and no user interaction required, so exploitation does not require an authenticated WordPress account or victim action.
What does the attack vector indicate about exposure?
The vulnerability has a network attack vector, indicating it may be exploitable remotely. Its attack complexity is rated high, so successful exploitation requires conditions beyond simply sending an arbitrary request.