CVE-2026-4020
CVSS 7.5 HIGH: the Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. EPSS 40% (99th percentile).
Vulnerabilities · 84 days ago
A site report that should stay internal is being handed to anyone on the internet, and it can include the keys to send mail as the victim site. Patching closes the bug, but it does not undo abuse of credentials already exposed through the report.
The flaw is CVE-2026-4020 in Gravity SMTP through 2.1.4. Its REST endpoint accepts unauthenticated requests because the permission check always returns true, and the resulting System Report can contain API keys, OAuth tokens, and third-party email-service credentials for providers such as Amazon SES, Google, Mailjet, Resend, and Zoho. Defiant says exploitation is active, and Wordfence has blocked more than 17 million attempts, with a spike on June 7.
The practical risk is mail fraud and phishing from trusted infrastructure, plus follow-on recon from the rest of the system report. Sites running Gravity SMTP 2.1.4 and older need to treat exposed email-service credentials as compromised, not just the plugin version.
CVSS 7.5 HIGH: the Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. EPSS 40% (99th percentile).
3 sources covering this story
Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
Vulnerable WordPress plugin iterations leak API keys, secrets, tokens, server information, and other data.
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Attackers are exploiting CVE-2026-4020 in Gravity SMTP to leak API keys, OAuth tokens, and system data from WordPress sites.
Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites.
Part of the PlainSec briefing for 2026-06-23