• News/
  • bleepingcomputer-20260619202502

Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin

BleepingComputer
·
Bill Toulas
·
Published Jun 19, 2026
·
Updated

Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites. The flaw is tracked as CVE-2026-4020 and received a medium severity rating. It affects all versions of the plugin from 2.1.4 and older and has been addressed in version 2.1.5, released on March 17. WordPress security company Defiant is warning that hackers are actively exploiting the vulnerability. The company's Wordfence firewall has blocked more than 17 million attempts against protected customers. The issue stems from an exposed REST API endpoint in Gravity SMTP, whose ‘permission_callback’ always returns ‘true,’ allowing unauthenticated GET requests to receive a comprehensive JSON “System Report” generated by the plugin. The exposed information may contain: Despite its medium-severity rating, the CVE-2026-4020 vulnerability can be exploited without authentication, and the exposed information can be used to steal email service credentials. This allows an attacker to impersonate the victim to third parties and also to gain detailed information about the site’s software stack and the potential vulnerabilities present. “The exposure of live third-party API credentials means an attacker could abuse the site’s connected email services, while the detailed system report significantly lowers the effort required to plan further attacks against the site,” Wordfence researchers warn. Wordfence says exploitation activity spiked on June 7,...

Read full article

Affected Software

2 affected components
Unknown Gravity SMTP<=2.1.4
Unknown Avada Builder<3.15.4
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main vulnerability discussed in this article?

The article discusses an unauthenticated information disclosure vulnerability in the Gravity SMTP WordPress plugin.

2

What is the CVE identifier for the reported vulnerability?

The vulnerability is tracked as CVE-2026-4020.

3

What versions of the Gravity SMTP plugin are affected by this vulnerability?

All versions of the Gravity SMTP plugin from 2.1.4 and older are affected.

4

How many WordPress sites are utilizing the Gravity SMTP plugin?

The Gravity SMTP plugin is active on approximately 100,000 WordPress sites.

5

What severity rating has been assigned to the CVE-2026-4020 vulnerability?

The vulnerability has received a medium severity rating.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203