CVE Tools

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

The Hacker NewsBy The Hacker News

Reported exploitedGravity SMTP

Our summary

Threat actors are actively exploiting a patched vulnerability in the WordPress plugin Gravity SMTP (installed on roughly 100,000 sites) to expose sensitive information. The issue, tracked as CVE-2026-4020 (CVSS 5.3), is an unauthenticated information disclosure flaw that can leak configuration details, secrets, and third-party email integration API keys/tokens via a REST endpoint. This matters because exposed credentials can be reused to send email through connected services, and attackers can also gather detailed system information to support follow-on attacks; the vendor fix is available in Gravity SMTP version 2.1.5.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store