Arbitrary File Deletion Vulnerability in Better Messages Plugin for WordPress
CVE-2026-16585
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-16585?
The Better Messages Plugin for WordPress is susceptible to an arbitrary file deletion vulnerability due to inadequate file path validation in its delete_sticker function. This issue affects all versions up to and including 2.15.19 and allows authenticated users with administrator-level access to remove arbitrary server files. An attacker could exploit this flaw by crafting a specially-designed URL that incorporates directory traversal techniques, bypassing the security checks intended to restrict deletions to the uploads directory. If critical files like wp-config.php are targeted, this can lead to severe consequences, including potential remote code execution.
Affected Version(s)
Better Messages β Chat Rooms, Group Chat, Private Messages & AI Chat Bots 0 <= 2.15.19