logo

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

ID: 55d359ad-cb62-540e-a13a-562727c10300

STIX ID: report--55d359ad-cb62-540e-a13a-562727c10300

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-06-21

Date Updated: 2026-06-24

...
...

A medium-severity (CVSS 5.3) information disclosure in the Gravity SMTP WordPress plugin (CVE-2026-4020) allowed unauthenticated retrieval of a ~365 KB JSON report exposing API keys, OAuth tokens, WordPress/site configuration, and database details; mass opportunistic exploitation began in late May 2026 with >17 million blocked requests and 412+ attacking IPs, and operators are advised to update to Gravity SMTP 2.1.5, rotate exposed credentials, block the endpoint via WAF if necessary, and audit email logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.