A vulnerability, which was classified as problematic, was found in wordplus Better Messages Plugin up to 2.15.19 on WordPress. This affects the function delete_sticker of the component File Path Validation. Such manipulation leads to relative path traversal.

This vulnerability is listed as CVE-2026-16585. The attack may be performed from remote. There is no available exploit.