CVE-2026-48906: Tassos Advanced Custom Fields
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
Affected products
- Tassos Advanced Custom Fields: from 1.0.0, up to and including 2.8.12; from 3.0.0, up to and including 3.1.3
- Tassos Convert Forms: from 1.0.0, up to and including 4.4.12; from 5.0.0, up to and including 5.1.5
- Tassos Engagebox: from 1.0.0, up to and including 6.3.11; from 7.0.0, up to and including 7.1.1
- Tassos Google Structured Data: from 1.0.0, up to and including 5.6.11; from 6.0.0, up to and including 6.1.9
- Tassos Mailchimp Auto-Subscribe: from 1.0.0, up to and including 5.0.5; from 5.1.0, up to and including 5.2.0
- Tassos Smile Pack: from 1.0.0, up to and including 1.2.6; from 2.0.0, up to and including 2.1.0
- Tassos Tassos Code Snippets: version 1.0.0 only
- Tassos Tassos Framework: from 1.0.0, up to and including 6.0.1
Published 2026-05-27. Last modified 2026-06-17.