← WordPress Vulnerabilities
WordPress security by component

tonda

tonda is a WordPress theme with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 24, 2026; the highest published CVSS base score is 8.1.

Theme slug: tonda

CVE-2026-28151: Tonda permits unauthenticated local file inclusion

Tonda before 2.6 permits an unauthenticated attacker to influence a local file-inclusion operation under an undisclosed high-complexity condition. Successful exploitation can expose local files and may execute included PHP, compromising site confidentiality, integrity, and availability.

PublishedAug 24, 2026
Known safe version2.6
Published vulnerabilities for tonda
Safe version
Aug 24, 2026 CVE-2026-28151
Tonda permits unauthenticated local file inclusion
Tonda before 2.6 permits an unauthenticated attacker to influence a local file-inclusion operation under an undisclosed high-complexity condition. Successful exploitation can expose local files and may execute included PHP, compromising site confidentiality, integrity, and availability.
2.6
CVE8.1
NVDPending
Jul 13, 2026 CVE-2026-57805
Tonda: Filesystem traversal
Tonda is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 2.5.
See mitigation notes
CVE7.5
NVDPending