Wordfence Says Gravity SMTP Flaw Is Being Actively Exploited
Wordfence says attackers are exploiting CVE-2026-4020 in Gravity SMTP, a WordPress plugin flaw that can leak system reports, API keys, and OAuth tokens.
Wordfence says attackers are actively exploiting a Gravity SMTP vulnerability that can expose WordPress system reports, API keys, secrets, and OAuth tokens from sites running vulnerable versions of the plugin.
Table Of Content
- What the vulnerability exposes
- Why a medium bug can become urgent
- Secret leakage widens the incident scope
- Attack volume is part of the signal
- What WordPress site owners should do now
- Update beyond the fixed floor
- Rotate exposed mail credentials
- Hunt for the endpoint in logs
- The broader WordPress lesson
- Sources
The Wordfence Threat Intelligence Team reported on June 17, 2026 that exploitation is targeting CVE-2026-4020, a sensitive-information-exposure flaw in Gravity SMTP. Wordfence says the plugin has an estimated 100,000 active installations and that vulnerable sites can leak detailed configuration data to unauthenticated visitors.
The issue is not framed as remote code execution, and Wordfence rates the vulnerability 5.3 medium. The operational risk is still serious because SMTP plugins often hold production mail credentials. A leaked API key or OAuth token can be enough to abuse or reconfigure an email integration if that credential has sufficient scope, or help an attacker chain the disclosure with other WordPress weaknesses.
What the vulnerability exposes
Wordfence identifies the affected software as Gravity SMTP versions up to and including 2.1.4, with 2.1.5 listed as the patched version in its vulnerability summary. The vendor’s Gravity SMTP changelog also lists version 2.1.5 on March 25, 2026 with “Added security enhancements,” followed by newer 2.1.6 and 2.2.0 releases.
The technical problem described by Wordfence is a REST API endpoint at /wp-json/gravitysmtp/v1/tests/mock-data whose permission callback unconditionally returns true. When the request includes the page=gravitysmtp-settings query parameter, Wordfence says Gravity SMTP populates connector data and the endpoint can return roughly 365 KB of JSON containing the plugin’s full System Report.
That report can include PHP and web-server details, the document root path, database server type and version, the WordPress version, active plugins and themes, configuration details, database table names, and email-integration credentials such as API keys, secrets, and OAuth tokens configured in the plugin.
Why a medium bug can become urgent
Secret leakage widens the incident scope
Security teams often rank vulnerabilities by whether they execute code. This one is a reminder that disclosure bugs can become high-priority incidents when they expose live credentials. If a mail provider token was present in Gravity SMTP and a vulnerable endpoint was reachable, the response should not stop at installing an update. The affected credential should be treated as potentially exposed until rotated or invalidated.
Attack volume is part of the signal
Wordfence says its firewall had already blocked more than 17 million exploit attempts against the vulnerability. It also says Wordfence Premium, Care, and Response users received a firewall rule on May 5, while free users received the same protection on June 4. Those dates matter for triage: a site that stayed on Gravity SMTP 2.1.4 or older after exploitation became visible should be reviewed as an exposure candidate, not just a patch-management miss.
What WordPress site owners should do now
Update beyond the fixed floor
The safest patch instruction is to update Gravity SMTP to the current vendor release available for the site, not merely to aim for the first fixed version named in the advisory. Wordfence’s summary names 2.1.5 as the patched version for CVE-2026-4020, while the official changelog shows later releases after that security-enhancement entry. Fleet owners should verify every production, staging, and abandoned WordPress instance rather than assuming only public flagship sites matter.
Rotate exposed mail credentials
After patching, administrators should review every email connector configured in Gravity SMTP and rotate any API keys, secrets, or OAuth tokens that may have been present while the vulnerable version was installed. Mail-provider dashboards should be checked for suspicious sending, new authorized apps, unusual API usage, or changes to allowed domains and sender identities.
Hunt for the endpoint in logs
Access logs, WAF logs, CDN logs, and managed WordPress security logs should be searched for requests containing /wp-json/gravitysmtp/v1/tests/mock-data and page=gravitysmtp-settings. A hit does not automatically prove credential theft, but it is enough to justify credential rotation and a deeper review of the site’s mail activity. Defenders should also preserve the logs before retention windows overwrite the evidence.
The broader WordPress lesson
Gravity SMTP is an email-delivery plugin, but the incident is really about where production secrets live. WordPress plugins that connect to SaaS services, mail providers, payment tools, CRMs, analytics platforms, or AI APIs often become credential stores. If their admin data can be reached without authentication, the impact can escape the WordPress site and move into third-party accounts.
For developers, the immediate lesson is simple: REST routes that expose configuration must require explicit authentication and capability checks. For operators, the lesson is equally practical: system reports are sensitive assets, not harmless diagnostics. They can reveal enough about versions, paths, plugins, and credentials to turn a medium disclosure bug into a useful attacker playbook.
Sources
- Wordfence: Attackers Actively Exploiting Sensitive Information Exposure Vulnerability in Gravity SMTP Plugin
- Gravity SMTP documentation: Gravity SMTP Changelog
- Featured image source: SC Guard on Flickr
Featured image: South Carolina National Guard Soldiers participate in a Department of Defense cyber defense exercise by SC Guard, marked Public Domain Mark 1.0; cropped and converted to WebP for sxz.io.








No Comment! Be the first one.