discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

Hackers are exploiting a vulnerability in the Gravity SMTP WordPress plugin to expose API keys and other sensitive data. The flaw, tracked as CVE-2026-4020, affects around 100,000 sites.

By Ravie Lakshmanan·Jun 20·thehackernews.com·2 min read

Intelligence analysis by Llama 3.3 70B

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Image: thehackernews.com

A medium-severity information disclosure flaw in the Gravity SMTP WordPress plugin is being exploited by hackers to extract sensitive data, including API keys and configuration details.

Why it matters

The vulnerability poses a significant risk to site owners, as exposed API keys and other sensitive data can be used to send email on behalf of the site and plan further attacks. The flaw affects around 100,000 sites, making it a widespread issue.

Imagine you have a secret box where you keep all your important information. The Gravity SMTP WordPress plugin vulnerability is like a hole in that box that allows bad people to look inside and take your secrets. They can use this information to send fake emails or plan other attacks against your site.

Analysis

Introduction to the Vulnerability

The Gravity SMTP WordPress plugin vulnerability, tracked as CVE-2026-4020, is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data. The flaw is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor to access it.

Impact of the Vulnerability

The vulnerability can be exploited by attackers to retrieve a wide range of information, including PHP version, loaded extensions, web server version, document root path, database server type and version, WordPress version, all active plugins with versions, active theme, WordPress configuration details, database table names, and API keys/tokens configured in the plugin. This information can be used to plan further attacks against the site, including sending email on behalf of the site and exploiting other vulnerabilities.

Exploitation and Mitigation

Bad actors have already started exploiting the vulnerability by sending unauthenticated HTTP GET requests to the vulnerable REST API endpoint with the ?page=gravitysmtp-settings query parameter. To mitigate the vulnerability, site owners should update the plugin to the latest version, rotate the credentials, and review server log files for suspicious requests. Wordfence has blocked over 17 million exploit attempts targeting CVE-2026-4020, highlighting the need for prompt action to protect against this vulnerability.

Key points

  • The Gravity SMTP WordPress plugin vulnerability is a medium-severity information disclosure flaw
  • The flaw affects around 100,000 sites
  • The vulnerability can be exploited to extract sensitive data, including API keys and configuration details
  • Site owners should update the plugin to the latest version and rotate the credentials to mitigate the vulnerability
The Upside

The patch for the vulnerability has been released, and site owners can update the plugin to protect against this flaw. By taking prompt action, site owners can prevent further exploitation and protect their sensitive data. Additionally, the widespread awareness of this vulnerability can lead to improved security practices and better protection against similar flaws in the future.

The Downside

The vulnerability has already been exploited by bad actors, and the exposed API keys and other sensitive data can be used to plan further attacks. If site owners do not take prompt action to update the plugin and rotate the credentials, they may face significant consequences, including compromised email services and further attacks against their site.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritywordpressvulnerabilityapi-securityemail-security

Author

Ravie Lakshmanan

Intelligence analysis by

Llama 3.3 70B

Published

Jun 20, 2026

Source

thehackernews.com

Share

Topics

securitywordpressvulnerabilityapi-securityemail-security

Related

More from this desk

Aug 26·bleepingcomputer.com

Critical Avada WordPress theme flaw enables zero-click RCE

Critical vulnerability in Avada WordPress theme can be exploited for arbitrary PHP code execution. CVE-2026-18431 affects Avada versions up to 7.16 and Fusion Builder plugin versions up to 3.16.

Aug 26·bleepingcomputer.com

New GPUThor attack defeats NVIDIA ECC protection for root access

Researchers demonstrate a new Rowhammer attack called GPUThor that can bypass ECC protections on NVIDIA GPUs, leading to DoS and privilege escalation.

Aug 26·thehackernews.com

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

FBI disrupts QTFY hacking platforms used by Chinese threat actors to target U.S. critical infrastructure and sensitive networks.

Aug 26·bleepingcomputer.com

Boston Scientific Announces Cyberattack Disrupts Global Operations

Boston Scientific reports a cyberattack that disrupted its IT systems, causing operational disruptions globally. The company is working to restore affected functions and systems access.