discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin

Hackers are exploiting a vulnerability in the Gravity SMTP WordPress plugin, affecting 100,000 sites. The flaw allows unauthenticated access to sensitive information.

By Bill Toulas·Jun 19·bleepingcomputer.com·1 min read

Intelligence analysis by Llama 3.3 70B

Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
Image: bleepingcomputer.com

The vulnerability, tracked as CVE-2026-4020, is a medium-severity issue that can be exploited without authentication, exposing API keys, secrets, and OAuth tokens.

Why it matters

The exploitation of this vulnerability can lead to the theft of email service credentials, allowing attackers to impersonate victims and gain detailed information about the site's software stack.

Imagine you have a mailbox where you receive important letters. The Gravity SMTP plugin is like a helper that makes sure those letters get delivered to the right place. But there's a problem with the helper that lets bad people look inside the mailbox and steal sensitive information.

Analysis

Introduction to the Vulnerability

The Gravity SMTP WordPress plugin is a popular choice for managing email services on WordPress sites. However, a recently discovered vulnerability has put over 100,000 sites at risk. The flaw, tracked as CVE-2026-4020, is a medium-severity issue that can be exploited without authentication.

The Impact of the Vulnerability

The vulnerability allows attackers to access sensitive information, including API keys, secrets, and OAuth tokens. This information can be used to steal email service credentials, allowing attackers to impersonate victims and gain detailed information about the site's software stack. The exposed information may also contain WordPress configuration details, including installed plugins, themes, and software versions, as well as server and PHP environment information.

The Exploitation of the Vulnerability

According to WordPress security company Defiant, hackers are actively exploiting the vulnerability. The company's Wordfence firewall has blocked over 17 million attempts against protected customers. The exploitation activity spiked on June 7, with 4 million requests being blocked that day. Similar activity was recorded for several days afterward. The security firm has listed the most prolific source IP addresses for exploit requests, which website administrators should add to their blocklists.

Key points

  • The Gravity SMTP WordPress plugin is affected by a medium-severity vulnerability
  • The vulnerability can be exploited without authentication
  • Over 100,000 sites are at risk
  • The vulnerability has been addressed in version 2.1.5 of the plugin
The Upside

The vulnerability has been addressed in version 2.1.5 of the Gravity SMTP plugin, and website administrators can protect their sites by updating to the latest version. Additionally, security companies like Defiant are actively monitoring the situation and providing protection for their customers.

The Downside

The exploitation of this vulnerability can have serious consequences, including the theft of email service credentials and the exposure of sensitive information. If left unaddressed, this vulnerability can lead to further attacks and potentially even a full site takeover.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritywordpressvulnerabilityexploit

Author

Bill Toulas

Intelligence analysis by

Llama 3.3 70B

Published

Jun 19, 2026

Source

bleepingcomputer.com

Share

Topics

securitywordpressvulnerabilityexploit

Related

More from this desk

Aug 26·bleepingcomputer.com

Critical Avada WordPress theme flaw enables zero-click RCE

Critical vulnerability in Avada WordPress theme can be exploited for arbitrary PHP code execution. CVE-2026-18431 affects Avada versions up to 7.16 and Fusion Builder plugin versions up to 3.16.

Aug 26·bleepingcomputer.com

New GPUThor attack defeats NVIDIA ECC protection for root access

Researchers demonstrate a new Rowhammer attack called GPUThor that can bypass ECC protections on NVIDIA GPUs, leading to DoS and privilege escalation.

Aug 26·thehackernews.com

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

FBI disrupts QTFY hacking platforms used by Chinese threat actors to target U.S. critical infrastructure and sensitive networks.

Aug 26·bleepingcomputer.com

Boston Scientific Announces Cyberattack Disrupts Global Operations

Boston Scientific reports a cyberattack that disrupted its IT systems, causing operational disruptions globally. The company is working to restore affected functions and systems access.