Vulnerabilities
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Cyber RTJune 20, 20263 min read

A security flaw in the Gravity SMTP WordPress plugin, affecting 100,000 sites, is being exploited by attackers. The vulnerability, CVE-2026-4020, allows unauthenticated access to sensitive data via a REST API endpoint. Attackers can extract configuration details, API keys, and more, enabling further attacks. A patch is available in version 2.1.5. Wordfence has blocked over 17 million exploit attempts, urging users to update and review logs.
A recently patched security flaw in the Gravity SMTP WordPress plugin, which is installed on approximately 100,000 websites, is being actively exploited by threat actors. This vulnerability, identified as CVE-2026-4020, has a CVSS score of 5.3, indicating a medium-severity risk. The flaw allows unauthenticated attackers to extract sensitive data, including configuration data, API keys, secrets, and OAuth tokens used in the plugin's email integrations.
The vulnerability arises from a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data, which has a permission_callback that always returns true. This flaw enables any unauthenticated visitor to access the endpoint. When the query parameter ?page=gravitysmtp-settings is appended, the plugin's register_connector_data() method populates internal connector data, resulting in the endpoint returning about 365 KB of JSON data containing the full System Report.
This exposure allows attackers to retrieve a wide range of information, such as the PHP version, loaded extensions, web server version, document root path, database server type and version, WordPress version, all active plugins with versions, active theme, WordPress configuration details, database table names, and API keys/tokens configured in the plugin. These API keys include those for services like Amazon SES, Google, Mailjet, Resend, and Zoho.
Attackers can exploit this information to harvest credentials, potentially sending emails on behalf of the site and gaining extensive insights into the site's software stack. Such detailed information can serve as a foundation for further attacks. The exposure of live third-party API credentials is particularly concerning, as it allows attackers to abuse the site's connected email services and reduces the effort needed to plan additional attacks.
A patch for this vulnerability was released in version 2.1.5 of the Gravity SMTP plugin. However, malicious actors have already begun exploiting the flaw by sending unauthenticated HTTP GET requests to the vulnerable REST API endpoint with the "?page=gravitysmtp-settings" query parameter. This allows them to obtain valuable site information without requiring authentication.
Wordfence, a security service, has blocked over 17 million exploit attempts targeting CVE-2026-4020. The initial exploit activity began in early May 2026 and spiked dramatically around June 6, 2026, reaching over 4,000,000 requests the following day. The exploit attempts have been traced back to several IP addresses, including 45.148.10.95, 193.32.162.60, and others.
Site owners using a vulnerable version of the Gravity SMTP plugin with third-party email integrations should assume their credentials have been compromised. It is crucial to update the plugin to the latest version and rotate the credentials immediately. Additionally, reviewing server log files for requests from the identified IP addresses is advised to detect any suspicious activity targeting the API endpoint.
For those interested in staying informed about similar security issues, following platforms like Google News, Twitter, and LinkedIn can provide access to exclusive content and updates on cybersecurity developments.


