CVE-2026-48906: Tassos Advanced Custom Fields

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.

Affected products

  • Tassos Advanced Custom Fields: from 1.0.0, up to and including 2.8.12; from 3.0.0, up to and including 3.1.3
  • Tassos Convert Forms: from 1.0.0, up to and including 4.4.12; from 5.0.0, up to and including 5.1.5
  • Tassos Engagebox: from 1.0.0, up to and including 6.3.11; from 7.0.0, up to and including 7.1.1
  • Tassos Google Structured Data: from 1.0.0, up to and including 5.6.11; from 6.0.0, up to and including 6.1.9
  • Tassos Mailchimp Auto-Subscribe: from 1.0.0, up to and including 5.0.5; from 5.1.0, up to and including 5.2.0
  • Tassos Smile Pack: from 1.0.0, up to and including 1.2.6; from 2.0.0, up to and including 2.1.0
  • Tassos Tassos Code Snippets: version 1.0.0 only
  • Tassos Tassos Framework: from 1.0.0, up to and including 6.0.1

Published 2026-05-27. Last modified 2026-06-17.