CVE-2026-4020
CVSS 7.5 HIGH: the Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. EPSS 2% (82º percentile).
Vulnerabilità · 99 giorni fa
Qui non c'è solo una fuga di informazioni. Se il System Report esce da un endpoint pubblico, l'attaccante non ottiene solo dettagli sul sito: può mettere le mani sulle credenziali dei servizi email collegati e inviare posta autenticata a nome del dominio colpito.
CVE-2026-4020 colpisce Gravity SMTP fino alla 2.1.4 ed è già sfruttata attivamente. Defiant e Wordfence segnalano ondate di richieste bloccate, mentre il report esposto può contenere API key, secret, OAuth token e credenziali per servizi come Amazon SES, Google, Mailjet, Resend e Zoho, oltre a dettagli utili sulla base di codice e sull'ambiente.
La correzione è nella 2.1.5. Se il report è stato raggiunto, le credenziali e i token passati da quel canale vanno considerati compromessi: il problema non finisce con la patch, perché l'abuso della posta resta possibile finché quei segreti restano validi.
CVSS 7.5 HIGH: the Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. EPSS 2% (82º percentile).
3 fonti che coprono questa storia
Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
Vulnerable WordPress plugin iterations leak API keys, secrets, tokens, server information, and other data.
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Attackers are exploiting CVE-2026-4020 in Gravity SMTP to leak API keys, OAuth tokens, and system data from WordPress sites.
Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites.
Part of the PlainSec briefing for 2026-06-23