logo

Hackers Exploit WordPress SMTP Plugin With 100,000+ Installs to Steal Sensitive Data

ID: e99d9e10-a2b4-5818-ae31-0e19e4b006e9

STIX ID: report--e99d9e10-a2b4-5818-ae31-0e19e4b006e9

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Divya

...
...

**Executive summary:** The Gravity SMTP WordPress plugin (<= 2.1.4) contains an unauthenticated REST endpoint (CVE-2026-4020) that returns full system reports — including API keys and OAuth tokens — to any requester; active, large-scale exploitation has generated millions of blocked requests and exposed over 100,000 sites, so administrators should update to 2.1.5, rotate any exposed credentials, and monitor access logs for suspicious requests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.