Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WordPress Gravity SMTP Flaw Exposes Critical Data

WordPress Gravity SMTP Flaw Exposes Critical Data

Posted on June 22, 2026 By CWS

Security researchers have identified a medium-severity flaw in the Gravity SMTP plugin for WordPress that is currently being exploited by cybercriminals to acquire comprehensive system information. The cybersecurity firm Defiant has raised the alarm about this vulnerability, which affects versions prior to 2.1.5 of the plugin.

Vulnerability Details and Impact

The Gravity SMTP plugin, designed to enhance email deliverability by integrating various SMTP providers and APIs, has a vulnerability tracked as CVE-2026-4020 with a CVSS score of 5.3. This flaw has been actively exploited since early May, affecting a REST API endpoint that inadvertently provides access to sensitive data without authentication.

When a specific parameter is added to a query, the affected API endpoint returns a JSON file containing a full system report. This report includes critical details such as PHP and WordPress versions, database information, active plugins and themes, and even API keys and tokens.

Exploitation and Attack Methods

The vulnerability exists because the REST API endpoint is part of a shared library that fails to enforce authentication or capability checks. As a result, attackers can easily retrieve credentials, enabling them to send emails on behalf of the site or gather reconnaissance data to exploit further vulnerabilities.

Defiant has monitored a significant increase in attack attempts targeting this flaw, with over 17 million attempts blocked by the firm. These attacks primarily involve unauthenticated GET requests aimed at extracting the System Report JSON object from the compromised endpoint.

Preventive Measures and Recommendations

WordPress site owners using the vulnerable versions of Gravity SMTP are strongly advised to upgrade to version 2.1.5 immediately. Additionally, it is crucial to review server logs for any suspicious requests to the vulnerable endpoint, as these attacks do not leave other noticeable traces.

For those using third-party email integrations such as Amazon SES or Google, it is recommended to rotate API keys, secrets, and OAuth tokens after updating the plugin to prevent unauthorized access. The proactive management of these credentials is essential to maintaining site security.

In summary, this security flaw in the Gravity SMTP plugin underscores the importance of regular plugin updates and vigilant monitoring of server activities. Site administrators must address this vulnerability promptly to safeguard their data and prevent potential breaches.

Security Week News Tags:CVE-2026-4020, Cybersecurity, data breach, Defiant, email security, Gravity SMTP, plugin security, REST API, Vulnerability, web security, WordPress

Post navigation

Previous Post: pgAdmin 4 Update: Security Enhancements and New Features
Next Post: Microsoft Prepares IT Admins for Windows 11 26H2 Update

Related Posts

Russian Qakbot Gang Leader Indicted in US Russian Qakbot Gang Leader Indicted in US Security Week News
Iranian APT Targets Android Users With New Variants of DCHSpy Spyware Iranian APT Targets Android Users With New Variants of DCHSpy Spyware Security Week News
NewCore Launches with  Million in Seed Funding NewCore Launches with $66 Million in Seed Funding Security Week News
SymJack Attack Exploits AI Coding Tools in Supply Chains SymJack Attack Exploits AI Coding Tools in Supply Chains Security Week News
Microsoft Patch Tuesday Covers WebDAV Flaw Marked as ‘Already Exploited’ Microsoft Patch Tuesday Covers WebDAV Flaw Marked as ‘Already Exploited’ Security Week News
Google Accelerates Chrome Releases to Bi-Weekly Schedule Google Accelerates Chrome Releases to Bi-Weekly Schedule Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Squid Proxy Flaw ‘Squidbleed’ Exposes User Data
  • OXLOADER Exploits Malicious Ads to Spread CastleStealer
  • WhatsApp Malware Targets Windows Users Globally
  • North Korean Hackers Linked to Major NPM Supply Chain Breach
  • Protect AI Agents from Legacy Infrastructure Surprises

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Squid Proxy Flaw ‘Squidbleed’ Exposes User Data
  • OXLOADER Exploits Malicious Ads to Spread CastleStealer
  • WhatsApp Malware Targets Windows Users Globally
  • North Korean Hackers Linked to Major NPM Supply Chain Breach
  • Protect AI Agents from Legacy Infrastructure Surprises

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark