Impact
The Tassos Framework Plugin permits an attacker to delete any file located on the site, resulting in loss of content, configuration files, or the ability to deploy malicious artifacts. This flaw falls under CWE‑284, an improper access control weakness, and is rated with a CVSS score of 9.3, indicating a critical threat to confidentiality, integrity, and availability.
Affected Systems
Affects all extensions released by tassos.gr, including Advanced Custom Fields, Convert Forms, EngageBox, Google Structured Data, MailChimp Auto‑Subscribe, the Novarain/Tassos Framework core module (plg_system_nrframework), Smile Pack, and Tassos Code Snippets. The vulnerability exists in any installation running a version earlier than 6.1.0, as indicated by the adviser's title.
Risk and Exploitability
Because the EPSS score is not available, the exact likelihood of exploitation in the wild is unknown; however, the high CVSS rating and the lack of KEV listing suggest that while the flaw is serious, it has not yet been widely abused. Attackers would need some level of access to the Joomla administrative interface or the ability to invoke the plugin's functionality. Once activated, the plugin can remove arbitrary files, potentially crippling the site or facilitating further compromise. Because no public exploit is documented, defensive actions should focus on remediation rather than detection.
OpenCVE Enrichment