PT-2025-49779 · Wbce Cms · Wbce Cms

Published

2025-12-09

·

Updated

2025-12-09

·

CVE-2025-67504

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WBCE CMS versions 1.6.4 and below
Description WBCE CMS uses the GenerateRandomPassword() function to create passwords using PHP's rand(). The rand() function is not cryptographically secure, which allows password sequences to be predicted or brute-forced. This can lead to user account compromise or privilege escalation if these passwords are used for new accounts or password resets.
Recommendations Update WBCE CMS to version 1.6.5.

Exploit

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2025-67504
GHSA-76GJ-PMVX-JCC6

Affected Products

Wbce Cms