All incidents

Gravity SMTP WordPress plugin flaw (CVE-2026-4020) exposes API keys

incidentclosedJun 17, 2026 — Jun 22, 2026
Gravity SMTP WordPress plugin flaw (CVE-2026-4020) exposes API keys

ATTACKERS are actively exploiting a flaw in the Gravity SMTP WordPress plugin that leaks API keys and other system data, putting thousands of sites at risk according to Wordfence. The vulnerability allows unauthenticated users to extract sensitive information via a poorly protected REST endpoint.

The issue is tracked as CVE-2026-4020 and carries a CVSS score of 7.5, rating it as high severity SecurityWeek reports. It affects all versions of the plugin prior to 2.1.5, where a missing authentication check on a REST API route lets anyone query internal settings.

Through this endpoint attackers can harvest live API credentials for mail services, logging frameworks and other integrations that sites rely on for daily operations The Hacker News notes. Wordfence first observed the activity in early May and has since blocked more than 17 million exploit attempts targeting the flaw.

SecurityOnline adds that the exploitation trend has spiked in recent weeks, with a noticeable increase in probes from multiple IP ranges their advisory states. Although no specific threat actor has been linked to the campaign, the volume of attempts indicates a broad, automated effort.

Site administrators should update the Gravity SMTP plugin to version 2.1.5 or later as the first step, which removes the vulnerable endpoint as advised by Wordfence. Any API keys that may have been exposed must be rotated immediately, and affected services should be reviewed for unauthorized access.

Additionally, consider disabling the REST API route if it is not needed for your workflow, deploy a web application firewall to filter suspicious requests, and monitor access logs for unexpected spikes or anomalous user agents.

Intelligence briefing updated Jun 22, 2026

CVE-2026-4020 7.5
Root sourcewww.wordfence.com
Timeline Coverage

Swipe to explore timeline