CVE-2026-79322: SQL Injection
SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id parameter to /mpblog/post/view.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any remote, unauthenticated attacker can target the affected endpoint. No authentication is required according to the available data.
What request input is involved in exploitation?
The vulnerable input is the id parameter sent to /mpblog/post/view. Exploitation can allow arbitrary SQL commands and reading arbitrary database contents.
Which installations should be considered affected?
Mageplaza Blog for Magento 2, package mageplaza/magento-2-blog-extension, is affected through version 4.3.2. The provided data does not identify any configuration prerequisite or mitigation.