TRENDING
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
Cast-iron late Qing dynasty coin minting press with a large flywheel, displayed in a museum case
October 9, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google
Rows of closed oak library card catalog drawers, each with a brass pull and a blank label holder
October 9, 2026
How to Encrypt PII in Python and Keep It Searchable With Blind Indexes
Close-up of a vintage Western Electric manual telephone switchboard with orange lamps, red patch cords plugged into jacks, a rotary dial and a black handset
October 9, 2026
Microsoft’s Agent Lightning v1.0 Turns Agent Training Into a Sample-Accounting Problem
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Two orange safety relief valves on grey pressure vessels in an industrial plant
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A lugworm lying on wet sand and mud at low tide
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 232 Posts
News 234 Posts
Learning Hub 204 Posts
Home/News/Wordfence Says Gravity SMTP Flaw Is Being Actively Exploited
News

Wordfence Says Gravity SMTP Flaw Is Being Actively Exploited

Wordfence says attackers are exploiting CVE-2026-4020 in Gravity SMTP, a WordPress plugin flaw that can leak system reports, API keys, and OAuth tokens.

June 17, 2026 4 Min Read
49

Wordfence says attackers are actively exploiting a Gravity SMTP vulnerability that can expose WordPress system reports, API keys, secrets, and OAuth tokens from sites running vulnerable versions of the plugin.

Table Of Content

  • What the vulnerability exposes
  • Why a medium bug can become urgent
  • Secret leakage widens the incident scope
  • Attack volume is part of the signal
  • What WordPress site owners should do now
  • Update beyond the fixed floor
  • Rotate exposed mail credentials
  • Hunt for the endpoint in logs
  • The broader WordPress lesson
  • Sources

The Wordfence Threat Intelligence Team reported on June 17, 2026 that exploitation is targeting CVE-2026-4020, a sensitive-information-exposure flaw in Gravity SMTP. Wordfence says the plugin has an estimated 100,000 active installations and that vulnerable sites can leak detailed configuration data to unauthenticated visitors.

The issue is not framed as remote code execution, and Wordfence rates the vulnerability 5.3 medium. The operational risk is still serious because SMTP plugins often hold production mail credentials. A leaked API key or OAuth token can be enough to abuse or reconfigure an email integration if that credential has sufficient scope, or help an attacker chain the disclosure with other WordPress weaknesses.

What the vulnerability exposes

Wordfence identifies the affected software as Gravity SMTP versions up to and including 2.1.4, with 2.1.5 listed as the patched version in its vulnerability summary. The vendor’s Gravity SMTP changelog also lists version 2.1.5 on March 25, 2026 with “Added security enhancements,” followed by newer 2.1.6 and 2.2.0 releases.

The technical problem described by Wordfence is a REST API endpoint at /wp-json/gravitysmtp/v1/tests/mock-data whose permission callback unconditionally returns true. When the request includes the page=gravitysmtp-settings query parameter, Wordfence says Gravity SMTP populates connector data and the endpoint can return roughly 365 KB of JSON containing the plugin’s full System Report.

That report can include PHP and web-server details, the document root path, database server type and version, the WordPress version, active plugins and themes, configuration details, database table names, and email-integration credentials such as API keys, secrets, and OAuth tokens configured in the plugin.

Why a medium bug can become urgent

Secret leakage widens the incident scope

Security teams often rank vulnerabilities by whether they execute code. This one is a reminder that disclosure bugs can become high-priority incidents when they expose live credentials. If a mail provider token was present in Gravity SMTP and a vulnerable endpoint was reachable, the response should not stop at installing an update. The affected credential should be treated as potentially exposed until rotated or invalidated.

Attack volume is part of the signal

Wordfence says its firewall had already blocked more than 17 million exploit attempts against the vulnerability. It also says Wordfence Premium, Care, and Response users received a firewall rule on May 5, while free users received the same protection on June 4. Those dates matter for triage: a site that stayed on Gravity SMTP 2.1.4 or older after exploitation became visible should be reviewed as an exposure candidate, not just a patch-management miss.

What WordPress site owners should do now

Update beyond the fixed floor

The safest patch instruction is to update Gravity SMTP to the current vendor release available for the site, not merely to aim for the first fixed version named in the advisory. Wordfence’s summary names 2.1.5 as the patched version for CVE-2026-4020, while the official changelog shows later releases after that security-enhancement entry. Fleet owners should verify every production, staging, and abandoned WordPress instance rather than assuming only public flagship sites matter.

Rotate exposed mail credentials

After patching, administrators should review every email connector configured in Gravity SMTP and rotate any API keys, secrets, or OAuth tokens that may have been present while the vulnerable version was installed. Mail-provider dashboards should be checked for suspicious sending, new authorized apps, unusual API usage, or changes to allowed domains and sender identities.

Hunt for the endpoint in logs

Access logs, WAF logs, CDN logs, and managed WordPress security logs should be searched for requests containing /wp-json/gravitysmtp/v1/tests/mock-data and page=gravitysmtp-settings. A hit does not automatically prove credential theft, but it is enough to justify credential rotation and a deeper review of the site’s mail activity. Defenders should also preserve the logs before retention windows overwrite the evidence.

The broader WordPress lesson

Gravity SMTP is an email-delivery plugin, but the incident is really about where production secrets live. WordPress plugins that connect to SaaS services, mail providers, payment tools, CRMs, analytics platforms, or AI APIs often become credential stores. If their admin data can be reached without authentication, the impact can escape the WordPress site and move into third-party accounts.

For developers, the immediate lesson is simple: REST routes that expose configuration must require explicit authentication and capability checks. For operators, the lesson is equally practical: system reports are sensitive assets, not harmless diagnostics. They can reveal enough about versions, paths, plugins, and credentials to turn a medium disclosure bug into a useful attacker playbook.

Sources

  • Wordfence: Attackers Actively Exploiting Sensitive Information Exposure Vulnerability in Gravity SMTP Plugin
  • Gravity SMTP documentation: Gravity SMTP Changelog
  • Featured image source: SC Guard on Flickr

Featured image: South Carolina National Guard Soldiers participate in a Department of Defense cyber defense exercise by SC Guard, marked Public Domain Mark 1.0; cropped and converted to WebP for sxz.io.

Tags:

API SecurityGravity SMTPPlugin VulnerabilitiesWordfenceWordPress Security

Share

People in a network operations center with monitoring displays, representing governed enterprise automation knowledge workflows
Previous Post

Ansible Automation Platform BYOK: A Readiness Checklist for Enterprise RAG

Coworking team reviewing notes around a laptop, representing WordPress agency operations work
Next Post

CloudLinux Survey Shows WordPress Agencies Are Becoming Infrastructure Operators

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
08 Oct
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
08 Oct
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
Trending
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
October 8, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
October 8, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A phone secured by a padlock, illustrating AI data-leak containment and security controls.
News

OpenAI’s Lockdown Mode Is a Data-Leak Brake, Not a Prompt-Injection Cure

June 8, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026