CVE Tools

Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin

BleepingComputerBy Bill Toulas

Reported exploitedGravity SMTP

Our summary

Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, impacting deployments on an estimated 100,000 sites. The issue is tracked as CVE-2026-4020 and affects all versions from 2.1.4 and earlier; it was addressed in version 2.1.5 (released March 17). By accessing an exposed REST API endpoint, attackers can retrieve a detailed JSON “System Report” that may include API keys, email service credentials for providers like Amazon SES, Google, Mailjet, Resend, and Zoho, and environment/configuration details—enabling account and credential abuse and helping plan further attacks.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store