ZeroHour

CVE-2026-48906

CVSS 4.0
9.3 critical
EPSS
<1%p19
Published
()
Modified
Description

The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.

Vendors
tassos
Products
advanced custom fields, convert forms, engagebox, google structured data, mailchimp auto-subscribe, smile pack, tassos code snippets, tassos framework
Weakness
CWE-284
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.