Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites. The flaw is tracked as CVE-2026-4020 and received a medium severity rating. It affects all versions of the plugin from 2.1.4 and older and has been addressed in version 2.1.5, released on March 17. WordPress security company Defiant is warning that hackers are actively exploiting the vulnerability. The company's Wordfence firewall has blocked more than 17 million attempts against protected customers. The issue stems from an exposed REST API endpoint in Gravity SMTP, whose ‘permission_callback’ always returns ‘true,’ allowing unauthenticated GET requests to receive a comprehensive JSON “System Report” generated by the plugin. The exposed information may contain: Despite its medium-severity rating, the CVE-2026-4020 vulnerability can be exploited without authentication, and the exposed information can be used to steal email service credentials. This allows an attacker to impersonate the victim to third parties and also to gain detailed information about the site’s software stack and the potential vulnerabilities present. “The exposure of live third-party API credentials means an attacker could abuse the site’s connected email services, while the detailed system report significantly lowers the effort required to plan further attacks against the site,” Wordfence researchers warn. Wordfence says exploitation activity spiked on June 7,...
Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
BleepingComputer
·Bill Toulas
·Published Jun 19, 2026
·Updated
Affected Software
2 affected components
Unknown Gravity SMTP<=2.1.4
Unknown Avada Builder<3.15.4
Frequently Asked Questions
1
What is the main vulnerability discussed in this article?
The article discusses an unauthenticated information disclosure vulnerability in the Gravity SMTP WordPress plugin.
2
What is the CVE identifier for the reported vulnerability?
The vulnerability is tracked as CVE-2026-4020.
3
What versions of the Gravity SMTP plugin are affected by this vulnerability?
All versions of the Gravity SMTP plugin from 2.1.4 and older are affected.
4
How many WordPress sites are utilizing the Gravity SMTP plugin?
The Gravity SMTP plugin is active on approximately 100,000 WordPress sites.
5
What severity rating has been assigned to the CVE-2026-4020 vulnerability?
The vulnerability has received a medium severity rating.