{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/better-messages/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-16585"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Better Messages – Chat Rooms, Group Chat, Private Messages \u0026 AI Chat Bots \u003c 2.15.19"],"_cs_severities":["high"],"_cs_tags":["wordpress","web-vulnerability","path-traversal","rce","file-deletion"],"_cs_type":"advisory","_cs_vendors":["Better Messages"],"content_html":"\u003cp\u003eA critical path traversal vulnerability, identified as CVE-2026-16585, affects all versions up to and including 2.15.19 of the Better Messages - Chat Rooms, Group Chat, Private Messages \u0026amp; AI Chat Bots plugin for WordPress. This flaw stems from insufficient file path validation within the \u003ccode\u003edelete_sticker\u003c/code\u003e function, which an authenticated attacker with administrator-level access can exploit. By crafting a URL that leverages path traversal sequences like \u003ccode\u003e../\u003c/code\u003e, an attacker can bypass the intended restrictions meant to limit deletions to the uploads directory. This bypass is possible because the \u003ccode\u003enormalize_sticker\u003c/code\u003e function, which processes URLs, uses \u003ccode\u003eesc_url_raw()\u003c/code\u003e which fails to strip these traversal sequences, allowing the malicious payload to be stored verbatim. Successful exploitation can lead to arbitrary file deletion on the server, including critical files such as \u003ccode\u003ewp-config.php\u003c/code\u003e, which can subsequently facilitate remote code execution.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker obtains or leverages existing administrator-level credentials for a WordPress instance running the vulnerable Better Messages plugin.\u003c/li\u003e\n\u003cli\u003eThe authenticated attacker crafts a malicious HTTP POST request targeting the plugin's \u003ccode\u003edelete_sticker\u003c/code\u003e functionality, likely via \u003ccode\u003eadmin-ajax.php\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe crafted request includes a URL parameter for the file path containing path traversal sequences (e.g., \u003ccode\u003e../../\u003c/code\u003e) embedded after a legitimate base uploads URL.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003enormalize_sticker\u003c/code\u003e function processes this URL, but its use of \u003ccode\u003eesc_url_raw()\u003c/code\u003e fails to sanitize or strip the \u003ccode\u003e../\u003c/code\u003e sequences, allowing the traversal payload to persist.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003edelete_sticker\u003c/code\u003e function then attempts to delete a file based on this manipulated path, which bypasses the intended directory restrictions.\u003c/li\u003e\n\u003cli\u003eThe vulnerability allows the function to delete arbitrary files on the WordPress server, outside the plugin's designated uploads directory.\u003c/li\u003e\n\u003cli\u003eDeletion of critical system files, such as \u003ccode\u003ewp-config.php\u003c/code\u003e, can lead to a denial of service, loss of sensitive data, or enable further exploitation, including remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-16585 leads to arbitrary file deletion on the affected WordPress server. An attacker, once authenticated as an administrator, can remove critical system files like \u003ccode\u003ewp-config.php\u003c/code\u003e. This can result in a denial of service for the website, expose sensitive configuration details, or potentially enable subsequent remote code execution, granting the attacker full control over the compromised WordPress instance. The vulnerability affects a widely used plugin, exposing a broad range of WordPress sites to this severe risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch the Better Messages - Chat Rooms, Group Chat, Private Messages \u0026amp; AI Chat Bots plugin to a version greater than 2.15.19 immediately to remediate CVE-2026-16585.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule provided in this brief to your SIEM and tune for your environment to detect exploitation attempts.\u003c/li\u003e\n\u003cli\u003eEnsure web server access logs are collected for the \u003ccode\u003ewebserver\u003c/code\u003e category, including full URL paths and query parameters, to enable detection of path traversal attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T07:19:41Z","date_published":"2026-07-28T07:19:41Z","id":"https://feed.craftedsignal.io/briefs/2026-07-wordpress-better-messages-file-deletion/","summary":"A path traversal vulnerability, CVE-2026-16585, in the Better Messages - Chat Rooms, Group Chat, Private Messages \u0026 AI Chat Bots plugin for WordPress allows authenticated administrators to delete arbitrary files on the server by bypassing file path validation, potentially leading to remote code execution.","title":"Arbitrary File Deletion Vulnerability in WordPress Better Messages Plugin","url":"https://feed.craftedsignal.io/briefs/2026-07-wordpress-better-messages-file-deletion/"}],"language":"en","title":"CraftedSignal Threat Feed - Better Messages","version":"https://jsonfeed.org/version/1.1"}