CVE-2023-51210: Webkul Bundle Product

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters in the UpdateProductQuantity function.

Affected products

  • Webkul Bundle Product: version 6.0.1 only

Published 2024-01-23. Last modified 2026-06-17.