Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
Hackers are exploiting a vulnerability in the Gravity SMTP WordPress plugin, affecting 100,000 sites. The flaw allows unauthenticated access to sensitive information.
Intelligence analysis by Llama 3.3 70B

The vulnerability, tracked as CVE-2026-4020, is a medium-severity issue that can be exploited without authentication, exposing API keys, secrets, and OAuth tokens.
Imagine you have a mailbox where you receive important letters. The Gravity SMTP plugin is like a helper that makes sure those letters get delivered to the right place. But there's a problem with the helper that lets bad people look inside the mailbox and steal sensitive information.
Analysis
Introduction to the Vulnerability
The Gravity SMTP WordPress plugin is a popular choice for managing email services on WordPress sites. However, a recently discovered vulnerability has put over 100,000 sites at risk. The flaw, tracked as CVE-2026-4020, is a medium-severity issue that can be exploited without authentication.
The Impact of the Vulnerability
The vulnerability allows attackers to access sensitive information, including API keys, secrets, and OAuth tokens. This information can be used to steal email service credentials, allowing attackers to impersonate victims and gain detailed information about the site's software stack. The exposed information may also contain WordPress configuration details, including installed plugins, themes, and software versions, as well as server and PHP environment information.
The Exploitation of the Vulnerability
According to WordPress security company Defiant, hackers are actively exploiting the vulnerability. The company's Wordfence firewall has blocked over 17 million attempts against protected customers. The exploitation activity spiked on June 7, with 4 million requests being blocked that day. Similar activity was recorded for several days afterward. The security firm has listed the most prolific source IP addresses for exploit requests, which website administrators should add to their blocklists.
Key points
- The Gravity SMTP WordPress plugin is affected by a medium-severity vulnerability
- The vulnerability can be exploited without authentication
- Over 100,000 sites are at risk
- The vulnerability has been addressed in version 2.1.5 of the plugin
The vulnerability has been addressed in version 2.1.5 of the Gravity SMTP plugin, and website administrators can protect their sites by updating to the latest version. Additionally, security companies like Defiant are actively monitoring the situation and providing protection for their customers.
The exploitation of this vulnerability can have serious consequences, including the theft of email service credentials and the exposure of sensitive information. If left unaddressed, this vulnerability can lead to further attacks and potentially even a full site takeover.



