LIVE NEWS
  • A mysterious gamma-ray stream comes from the Milky Way’s center. Could dark matter have something to do with it?
  • Abiy Ahmed wins Ethiopian election but fears grow of renewed conflict
  • Why Capital Is Flowing Into XRP, SOL, and HYPE Instead of BTC and ETH
  • Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
  • Bitcoin on track for weekly losses amid Iran uncertainty, rate jitters By Investing.com
  • Half of France under red heat alert as alcohol banned at street music festival
  • Iran closes the Strait of Hormuz amid ceasefire deal violation
  • Defense Business Brief: Tech Summit recap; Invoking the Defense Production Act; and INDOPACOM’s name change
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Cybersecurity

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

primereportsBy primereportsJune 21, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Share
Facebook Twitter LinkedIn Pinterest Email


Ravie LakshmananJun 20, 2026Vulnerability / Web Security

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that’s installed on about 100,000 sites.

The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data, such as configuration data, API keys, secrets, and OAuth tokens configured for the plugin’s email integrations.

“This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor to access it,” Wordfence said.

Cybersecurity

“When the ?page=gravitysmtp-settings query parameter is appended, the plugin’s register_connector_data() method populates internal connector data, causing the endpoint to return approximately 365 KB of JSON containing the full System Report.”

As a result, an unauthenticated attacker can weaponize this issue to retrieve a wide range of information, including –

  • PHP version
  • Loaded extensions
  • Web server version
  • Document root path
  • Database server type and version
  • WordPress version
  • All active plugins with versions
  • Active theme
  • WordPress configuration details
  • Database table names
  • API keys/tokens configured in the plugin, such as Amazon SES, Google, Mailjet, Resend, and Zoho

Attackers could then leverage this exposure to harvest credentials that could be abused to send email on behalf of the site, as well as glean extensive details of the site’s software stack, which could act as a foundation for follow-on attacks.

“As with all sensitive information exposure vulnerabilities, the impact depends on what data is exposed,” Wordfence added. “In this case, the exposure of live third-party API credentials means an attacker could abuse the site’s connected email services, while the detailed system report significantly lowers the effort required to plan further attacks against the site.”

A patch for the vulnerability has been released in version 2.1.5 of the plugin. Bad actors have already pounced on the defect by sending unauthenticated HTTP GET requests to the vulnerable REST API endpoint with the “?page=gravitysmtp-settings” query parameter, causing the server to return valuable information about the site without requiring any authentication.

Cybersecurity

Wordfence has blocked more than 17 million exploit attempts targeting CVE-2026-4020 to date, with initial activity commencing at the start of May 2026 before spiking up dramatically around June 6, 2026, touching a high of over 4,000,000 requests a day later. The exploit efforts have originated from the following IP addresses –

  • 45.148.10.95
  • 193.32.162.60
  • 176.65.148.139
  • 173.199.90.188
  • 45.148.10.120
  • 185.8.107.155
  • 185.8.106.37
  • 185.8.106.92
  • 185.8.106.145
  • 176.65.148.30

Site owners running a vulnerable version of the Gravity SMTP plugin and have configured third-party email integrations should assume compromise, and rotate the credentials after updating the plugin to the latest version as soon as possible. It’s also advised to review server log files for requests originating from the aforementioned IP addresses for any suspicious requests to the API endpoint.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleBitcoin on track for weekly losses amid Iran uncertainty, rate jitters By Investing.com
Next Article Why Capital Is Flowing Into XRP, SOL, and HYPE Instead of BTC and ETH
primereports
  • Website

Related Posts

Cybersecurity

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm – Krebs on Security

June 21, 2026
Cybersecurity

French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation

June 20, 2026
Cybersecurity

Klue breach lead to Salesforce data theft, Huntress affected

June 20, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • A mysterious gamma-ray stream comes from the Milky Way’s center. Could dark matter have something to do with it?
  • Abiy Ahmed wins Ethiopian election but fears grow of renewed conflict
  • Why Capital Is Flowing Into XRP, SOL, and HYPE Instead of BTC and ETH
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.