CVE-2025-67504
CRITICALWbce Cms < 1.6.5 - Privilege Escalation
Title source: ruleDescription
WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand() is not cryptographically secure, which allows password sequences to be predicted or brute-forced. This can lead to user account compromise or privilege escalation if these passwords are used for new accounts or password resets. The vulnerability is fixed in version 1.6.5.
Scores
CVSS v3
9.1
EPSS
0.0007
EPSS Percentile
20.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Classification
CWE
CWE-331
CWE-338
Status
published
Affected Products (1)
wbce/wbce_cms
< 1.6.5
Timeline
Published
Dec 09, 2025
Tracked Since
Feb 18, 2026