CVE-2025-67504

CRITICAL

Wbce Cms < 1.6.5 - Privilege Escalation

Title source: rule

Description

WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand() is not cryptographically secure, which allows password sequences to be predicted or brute-forced. This can lead to user account compromise or privilege escalation if these passwords are used for new accounts or password resets. The vulnerability is fixed in version 1.6.5.

Scores

CVSS v3 9.1
EPSS 0.0007
EPSS Percentile 20.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Classification

CWE
CWE-331 CWE-338
Status published

Affected Products (1)

wbce/wbce_cms < 1.6.5

Timeline

Published Dec 09, 2025
Tracked Since Feb 18, 2026