Arbitrary File Deletion Vulnerability in Better Messages Plugin for WordPress
CVE-2026-16585

7.2HIGH

What is CVE-2026-16585?

The Better Messages Plugin for WordPress is susceptible to an arbitrary file deletion vulnerability due to inadequate file path validation in its delete_sticker function. This issue affects all versions up to and including 2.15.19 and allows authenticated users with administrator-level access to remove arbitrary server files. An attacker could exploit this flaw by crafting a specially-designed URL that incorporates directory traversal techniques, bypassing the security checks intended to restrict deletions to the uploads directory. If critical files like wp-config.php are targeted, this can lead to severe consequences, including potential remote code execution.

Affected Version(s)

Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots 0 <= 2.15.19

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.