High severity8.8OSV Advisory· Published Dec 11, 2025· Updated Jun 17, 2026
CVE-2025-34506
CVE-2025-34506
Description
WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a specially designed ZIP module with embedded PHP reverse shell code to gain remote system access when the module is installed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/52132nvdExploitThird Party AdvisoryVDB Entry
- youtu.be/Dhg5gRe9DzsnvdExploit
- www.vulncheck.com/advisories/wbce-cms-authenticated-remote-code-execution-via-module-uploadnvdThird Party Advisory
- wbce-cms.orgnvdProduct
News mentions
0No linked articles in our index yet.