Wbce Cms · Wbce Cms · CVE-2025-34506
**Name of the Vulnerable Software and Affected Versions**
WBCE CMS versions prior to 1.6.3
WBCE CMS version 1.6.3
**Description**
WBCE CMS versions 1.6.3 and earlier have a flaw that permits administrators to execute code remotely by uploading malicious modules. An attacker can create a ZIP module containing PHP reverse shell code, and upon installation, gain access to the system. The vulnerability requires authentication.
**Recommendations**
Update WBCE CMS to a version later than 1.6.3.