CVE-2025-67504
Last modified
CVE-2025-67504 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand() is not cryptographically secure, which allows password sequences to be predicted or brute-forced. This can lead to user account compromise or privilege escalation if these passwords are used for new accounts or password resets. The vulnerability is fixed in version 1.6.5.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wbce | Wbce Cms | < 1.6.5 |
References
- https://cwe.mitre.org/data/definitions/338.htmlTechnical Description
- https://github.com/WBCE/WBCE_CMS/releases/tag/1.6.5Release Notes
- https://github.com/WBCE/WBCE_CMS/security/advisories/GHSA-76gj-pmvx-jcc6Exploit, Vendor Advisory
- https://github.com/WBCE/WBCE_CMS/security/advisories/GHSA-76gj-pmvx-jcc6Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-67504?
How severe is CVE-2025-67504?
How do I fix CVE-2025-67504?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-67499The CNI portmap plugin allows containers to emulate opening …3.6
- CVE-2025-6750A vulnerability, which was classified as problematic, has be…3.3
- CVE-2025-67500Mastodon is a free, open-source social network server based …3.7
- CVE-2025-67501WeGIA is an open source Web Manager for Institutions with a …8.8
- CVE-2025-67502Taguette is an open source qualitative research tool. In ver…6.1
- CVE-2025-67503Rejected reason: This CVE is a duplicate of another CVE.
- CVE-2025-67505Okta Java Management SDK facilitates interactions with the O…8.4
- CVE-2025-67506PipesHub is a fully extensible workplace AI platform for ent…9.8
- CVE-2025-67507Filament is a collection of full-stack components for accele…8.1
- CVE-2025-67508gardenctl is a command-line client for the Gardener which co…8.4
- CVE-2025-67509Neuron is a PHP framework for creating and orchestrating AI …8.2
- CVE-2025-6751A vulnerability, which was classified as critical, was found…8.8
Are you affected by CVE-2025-67504?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
