cvedb.io
CVE-2025-67504
CRITICAL · CVSS 9.1
EPSS exploitation probability: 0%
Published 2025-12-09T16:18:24.237 · Last modified 2026-06-17T09:57:45.153

Summary

WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand() is not cryptographically secure, which allows password sequences to be predicted or brute-forced. This can lead to user account compromise or privilege escalation if these passwords are used for new accounts or password resets. The vulnerability is fixed in version 1.6.5.

Affected products

wbce — wbce_cms

Does this affect you?

Add your gear to cvedb and we'll alert you only when wbce ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.