Executive brief
The Better Messages plugin for WordPress, which provides chat and messaging features, contains a security flaw that allows administrators to delete any file on the web server. By deleting critical system files like the site's configuration file, an attacker can gain full control over the website or cause a total service outage. This could lead to the theft of customer data or the complete takeover of the web server.
Technical details
The Better Messages plugin for WordPress is vulnerable to arbitrary file deletion due to a path traversal flaw in the delete_sticker function. While the plugin attempts to restrict deletions to the uploads directory, the normalize_sticker function uses esc_url_raw(), which fails to strip '../' sequences. An authenticated attacker with administrator-level privileges can craft a malicious URL that bypasses prefix checks, allowing them to delete sensitive files such as wp-config.php. Deleting such files can lead to a site reset or remote code execution. The issue is present in all versions up to and including 2.15.19 and was addressed in subsequent updates.
Affected products
- wordplus Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots <= 2.15.19
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory
References
- https://plugins.trac.wordpress.org/browser/bp-better-messages/tags/2.15.19/addons/stickers/pack-manager.php
- https://plugins.trac.wordpress.org/browser/bp-better-messages/tags/2.15.19/addons/stickers/rest.php
- https://plugins.trac.wordpress.org/browser/bp-better-messages/tags/2.15.19/addons/stickers/rest.php
- https://plugins.trac.wordpress.org/browser/bp-better-messages/tags/2.15.19/addons/stickers/rest.php
- https://plugins.trac.wordpress.org/changeset/3623636/bp-better-messages/trunk/addons/stickers/rest.php?old=3527109&old_path=bp-better-messages%2Ftrunk%2Faddons%2Fstickers%2Frest.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/e9274957-7584-4df6-bb2a-d745510f5033?source=cve