What is CVE-2026-16585?
CVE-2026-16585 is a vulnerability in the 'Better Messages' plugin for WordPress up to version 2.15.19, allowing arbitrary file deletion via the `delete_sticker` function due to insufficient file path validation. This can be exploited by authenticated users to delete critical files, potentially leading to site compromise. Immediate update to the latest patched version is recommended.
Azərbaycanca: CVE-2026-16585, WordPress üçün "Better Messages" plaginin 2.15.19-a qədər bütün versiyalarını təsir edən zəiflikdir. `delete_sticker` funksiyasında `file path` doğrulamasının olmaması səbəbilə autentifikasiya olunmuş istifadəçi ixtiyari fayl silməsi həyata keçirə bilər. Plagin dərhal ən son təhlükəsiz versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What plugin does CVE-2026-16585 affect in WordPress?
This vulnerability affects all versions of the 'Better Messages' plugin for WordPress up to version 2.15.19.
How to protect against CVE-2026-16585?
The plugin should be immediately updated to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.