CVE-2026-4020
CVSS 7.5 HIGH: the Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. EPSS 2% (82º percentile).
Vulnerabilità ed exploit · Furto di credenziali
Qui non c'è solo una fuga di informazioni. Se il System Report esce da un endpoint pubblico, l'attaccante non ottiene solo dettagli sul sito: può mettere le mani sulle credenziali dei servizi email collegati e inviare posta autenticata a nome del dominio colpito.
CVE-2026-4020 colpisce Gravity SMTP fino alla 2.1.4 ed è già sfruttata attivamente. Defiant e Wordfence segnalano ondate di richieste bloccate, mentre il report esposto può contenere API key, secret, OAuth token e credenziali per servizi come Amazon SES, Google, Mailjet, Resend e Zoho, oltre a dettagli utili sulla base di codice e sull'ambiente.
La correzione è nella 2.1.5. Se il report è stato raggiunto, le credenziali e i token passati da quel canale vanno considerati compromessi: il problema non finisce con la patch, perché l'abuso della posta resta possibile finché quei segreti restano validi.
3 fonti · 22 giu
CVSS 7.5 HIGH: the Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. EPSS 2% (82º percentile).
SecurityWeek
Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
Vulnerable WordPress plugin iterations leak API keys, secrets, tokens, server information, and other data.
originaleThe Hacker News
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Attackers are exploiting CVE-2026-4020 in Gravity SMTP to leak API keys, OAuth tokens, and system data from WordPress sites.
originaleBleepingComputer
Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites.
originalePart of the PlainSec briefing for 2026-06-23
Every edition of this story: Gravity SMTP espone le chiavi della posta del sito