Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Gravity SMTP Plugin Vulnerability Exposes API Keys

Gravity SMTP Plugin Vulnerability Exposes API Keys

Posted on June 20, 2026 By CWS

The Gravity SMTP WordPress plugin, installed on approximately 100,000 websites, has been found vulnerable due to a security flaw recently patched. This vulnerability, identified as CVE-2026-4020 and rated with a CVSS score of 5.3, allows unauthorized users to extract sensitive information, including API keys, configuration settings, and OAuth tokens used in the plugin’s email integrations.

Understanding the Vulnerability

The flaw stems from a REST API endpoint located at /wp-json/gravitysmtp/v1/tests/mock-data, which has a permission_callback function that indiscriminately grants access to anyone, regardless of authentication status. When the query parameter ?page=gravitysmtp-settings is added, the plugin’s register_connector_data() method provides internal connector data. This results in the endpoint delivering roughly 365 KB of JSON data, revealing a comprehensive System Report.

This security lapse permits attackers to obtain a wide array of information, including the PHP version, loaded extensions, web server version, and WordPress configuration details. Additionally, it exposes all active plugins, their versions, and the database server type and version. Most critically, API keys and tokens for services like Amazon SES, Google, Mailjet, Resend, and Zoho can be compromised.

Implications of the Data Exposure

Exposing such sensitive information could enable attackers to exploit email services connected to the site and gather extensive data on the site’s software infrastructure. This detailed information simplifies the process of planning further attacks on the affected sites. As Wordfence notes, the severity of the impact relies on the type of data exposed, particularly emphasizing the risk posed by live third-party API credentials.

Attackers have been quick to exploit this vulnerability, issuing unauthenticated HTTP GET requests to the vulnerable API endpoint, appending the ?page=gravitysmtp-settings query parameter. This action allows them to extract significant information about the site without needing any authentication.

Response and Mitigation

A fix for this vulnerability is available in version 2.1.5 of the Gravity SMTP plugin. Despite the patch, malicious actors have been actively targeting this flaw, as evidenced by over 17 million blocked exploit attempts by Wordfence. The attacks began in early May 2026, escalating dramatically around June 6, 2026, with a peak of more than 4 million requests in a single day. The attacks have originated from several IP addresses, including 45.148.10.95, 193.32.162.60, and others.

Site administrators using a susceptible version of the Gravity SMTP plugin, especially those with third-party email integrations, should assume their credentials may be compromised. It is crucial to update the plugin immediately and rotate any exposed credentials. Additionally, reviewing server logs for any suspicious activity from the listed IP addresses is advised to ensure site security.

Addressing this vulnerability promptly is essential to safeguarding your site from potential security breaches and protecting sensitive information from unauthorized access.

The Hacker News Tags:API keys exposure, Gravity SMTP, plugin vulnerability, web security, WordPress security

Post navigation

Previous Post: AutoJack Exploit Risks AI Agents with Code Execution
Next Post: Macron Advocates Global AI Regulation at G7 Summit

Related Posts

The Crucial Role of Initial Decisions in Incident Response The Crucial Role of Initial Decisions in Incident Response The Hacker News
New ClickFix Campaign Exploits Sites for MIMICRAT Deployment New ClickFix Campaign Exploits Sites for MIMICRAT Deployment The Hacker News
Trojan VPNs Spread via SEO Poisoning, Microsoft Warns Trojan VPNs Spread via SEO Poisoning, Microsoft Warns The Hacker News
North Korean Hackers Exploit VS Code for New Malware North Korean Hackers Exploit VS Code for New Malware The Hacker News
China’s Storm-1175 Launches Rapid Medusa Ransomware Attacks China’s Storm-1175 Launches Rapid Medusa Ransomware Attacks The Hacker News
CISA Adds Citrix NetScaler CVE-2025-5777 to KEV Catalog as Active Exploits Target Enterprises CISA Adds Citrix NetScaler CVE-2025-5777 to KEV Catalog as Active Exploits Target Enterprises The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Macron Advocates Global AI Regulation at G7 Summit
  • Gravity SMTP Plugin Vulnerability Exposes API Keys
  • AutoJack Exploit Risks AI Agents with Code Execution
  • CISA Urges Fortinet Device Security Amid FortiBleed Threat
  • Gentlemen RaaS Targets Security with EDR Framework

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Macron Advocates Global AI Regulation at G7 Summit
  • Gravity SMTP Plugin Vulnerability Exposes API Keys
  • AutoJack Exploit Risks AI Agents with Code Execution
  • CISA Urges Fortinet Device Security Amid FortiBleed Threat
  • Gentlemen RaaS Targets Security with EDR Framework

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark