Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
ID: 55d359ad-cb62-540e-a13a-562727c10300
STIX ID: report--55d359ad-cb62-540e-a13a-562727c10300
Feed Name: CosmicBytez Labs
A medium-severity (CVSS 5.3) information disclosure in the Gravity SMTP WordPress plugin (CVE-2026-4020) allowed unauthenticated retrieval of a ~365 KB JSON report exposing API keys, OAuth tokens, WordPress/site configuration, and database details; mass opportunistic exploitation began in late May 2026 with >17 million blocked requests and 412+ attacking IPs, and operators are advised to update to Gravity SMTP 2.1.5, rotate exposed credentials, block the endpoint via WAF if necessary, and audit email logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
