logo

Active Gravity SMTP Vulnerability Exploited in the Wild

ID: 8b9227d2-8ce1-5403-be6d-c9a143f76f07

STIX ID: report--8b9227d2-8ce1-5403-be6d-c9a143f76f07

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Do Son

...
...

A critical information-exposure vulnerability (CVE-2026-4020) in the Gravity SMTP WordPress plugin (<= 2.1.4) exposes a site's full System Report — including API keys, secrets, and OAuth tokens — via an unauthenticated REST API endpoint. The flaw is trivial to exploit and is being actively abused at scale (millions of blocked attempts, multiple high-volume IPs); site owners are urged to update to 2.1.5 immediately and rotate any potentially compromised credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.