Vulnerability Description
The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tassos | Advanced Custom Fields | >= 1.0.0, <= 2.8.12 |
| Tassos | Convert Forms | >= 1.0.0, <= 4.4.12 |
| Tassos | Engagebox | >= 1.0.0, <= 6.3.11 |
| Tassos | Google Structured Data | >= 1.0.0, <= 5.6.11 |
| Tassos | Mailchimp Auto-Subscribe | >= 1.0.0, <= 5.0.5 |
| Tassos | Smile Pack | >= 1.0.0, <= 1.2.6 |
| Tassos | Tassos Code Snippets | 1.0.0 |
| Tassos | Tassos Framework | >= 1.0.0, <= 6.0.1 |
Related Weaknesses (CWE)
References
- https://tassos.grProduct
FAQ
What is CVE-2026-48906?
CVE-2026-48906 is a vulnerability with a CVSS score of 8.1 (HIGH). The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
How severe is CVE-2026-48906?
CVE-2026-48906 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-48906?
Check the references section above for vendor advisories and patch information. Affected products include: Tassos Advanced Custom Fields, Tassos Convert Forms, Tassos Engagebox, Tassos Google Structured Data, Tassos Mailchimp Auto-Subscribe.