A site report that should stay internal is being handed to anyone on the internet, and it can include the keys to send mail as the victim site. Patching closes the bug, but it does not undo abuse of credentials already exposed through the report.
The flaw is CVE-2026-4020 in Gravity SMTP through 2.1.4. Its REST endpoint accepts unauthenticated requests because the permission check always returns true, and the resulting System Report can contain API keys, OAuth tokens, and third-party email-service credentials for providers such as Amazon SES, Google, Mailjet, Resend, and Zoho. Defiant says exploitation is active, and Wordfence has blocked more than 17 million attempts, with a spike on June 7.
The practical risk is mail fraud and phishing from trusted infrastructure, plus follow-on recon from the rest of the system report. Sites running Gravity SMTP 2.1.4 and older need to treat exposed email-service credentials as compromised, not just the plugin version.