CVE-2025-67504

CRITICAL

Wbce Cms < 1.6.5 - Privilege Escalation

Title source: rule
STIX 2.1

Description

WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand() is not cryptographically secure, which allows password sequences to be predicted or brute-forced. This can lead to user account compromise or privilege escalation if these passwords are used for new accounts or password resets. The vulnerability is fixed in version 1.6.5.

Scores

CVSS v3 9.1
EPSS 0.0008
EPSS Percentile 23.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-331 CWE-338
Status published
Products (1)
wbce/wbce_cms < 1.6.5
Published Dec 09, 2025
Tracked Since Feb 18, 2026