www.securityweek.com 6/22/2026, 12:11:46 PM · external

Gravity SMTP Plugin Flaw (CVE-2026-4020) Exposes Site Data

Gravity SMTP Plugin Flaw (CVE-2026-4020) Exposes Site Data
Developing story incident 3 articles tracked
Gravity SMTP WordPress plugin flaw (CVE-2026-4020) exposes API keys
CyberSIXT Evidence Panel
Primary Source wordfence.com
CISA KEV Not in KEV
Patch Patch Status Unknown

THREAT actors are exploiting a medium-severity vulnerability (CVE-2026-4020) in the Gravity SMTP WordPress plugin, affecting versions before 2.1.5. This vulnerability allows unauthenticated users to access sensitive system information through a REST API endpoint that lacks proper authentication checks. Since early May, attackers have been able to steal complete system details, leading Defiant to block over 17 million exploit attempts. Website administrators are urged to update to version 2.1.5 and rotate any exposed API credentials.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline