CVE · High

CVE-2026-16585 — Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.15.20

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16585 Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.15.20 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.2 < 2.15.20 2.15.20 2026-07-27

CVE-2026-16585

The Better Messages plugin for WordPress contains a vulnerability that allows authenticated attackers with administrator-level access to delete any file on the server. This occurs due to a weakness in the way the plugin handles file paths, specifically in the delete_sticker function, which can be bypassed by crafting a malicious URL that includes directory traversal sequences. As a result, attackers can potentially delete sensitive files, such as the wp-config.php file, which can lead to remote code execution.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.