Impact
Mageplaza Blog Extension for Magento 2 is vulnerable to an unauthenticated SQL injection flaw through the id parameter in the /mpblog/post/view URL. Attackers can supply arbitrary SQL statements that are executed against the Magento database, enabling them to read, modify, or delete data. The injected payload can compromise database confidentiality, integrity, and potentially availability by allowing arbitrary data manipulation. This vulnerability belongs to the classic SQL injection family, identified by CWE‑89.
Affected Systems
All installations of the Mageplaza Blog Extension version 4.3.2 or earlier are affected. The flaw exists in the RelatedProduct block component of the /mpblog/post/view route across these versions.
Risk and Exploitability
The vulnerability is exploitable remotely without authentication and requires only standard HTTP requests. The CVSS score is 8.6, indicating high severity. Evidence of exploitation is not available (EPSS score not provided), and the issue is not listed in the CISA KEV catalog. Given its ability to execute arbitrary database commands, the risk is high, especially for installations with sensitive data or where the database is exposed to the public network. Attackers can achieve full control over the database content and potentially leverage it for further compromise.
OpenCVE Enrichment