Relevance: primary · Type: event
Confidence100%
Threat actors are exploiting a vulnerability in the Gravity SMTP WordPress plugin to steal system details.
Relevance: primary · Type: action
Confidence100%
Defiant warns that the vulnerability allows attackers to steal complete system details.
Relevance: supporting · Type: background
Confidence100%
Gravity SMTP is an email deliverability plugin for WordPress that integrates with multiple SMTP providers and API-based services.
Relevance: primary · Type: background
Confidence100%
All versions of the Gravity SMTP plugin before version 2.1.5 are affected by the vulnerability.
Relevance: primary · Type: background
Confidence100%
The vulnerability is tracked as CVE-2026-4020.
Relevance: supporting · Type: background
Confidence100%
The vulnerability has a CVSS score of 5.3.
Relevance: primary · Type: event
Confidence100%
The vulnerability has been exploited in the wild since early May.
Relevance: primary · Type: background
Confidence100%
The issue impacts a REST API endpoint that unconditionally returns true, making it accessible to any unauthenticated user.
Relevance: supporting · Type: background
Confidence100%
If a specific parameter is appended to a query, the endpoint returns internal connector data in JSON format.
Relevance: primary · Type: background
Confidence100%
The exposed data contains a full system report including PHP and WordPress version, loaded extensions, web server details, document root path, database details, active plugins and theme, WordPress configuration details, and configured API keys or tokens.
Relevance: supporting · Type: background
Confidence100%
The bug exists because the impacted REST AI endpoint does not perform authentication or capability checks.
Defiant, WordPress security firm
Relevance: primary · Type: quote
Confidence100%
"This makes it possible for unauthenticated attackers to harvest credentials that could be used to send email on behalf of the site, as well as to gather detailed reconnaissance about the site’s software stack that can be leveraged to identify and target other vulnerabilities."
Relevance: primary · Type: event
Confidence100%
Attackers have been sending unauthenticated GET requests to the vulnerable endpoint to retrieve the full System Report JSON object.
Relevance: primary · Type: event
Confidence100%
Defiant observed a surge in attacks targeting CVE-2026-4020 in June.
Relevance: primary · Type: action
Confidence100%
Defiant has blocked over 17 million exploit attempts to date.
Relevance: supporting · Type: action
Confidence100%
Defiant advises site owners to update Gravity SMTP deployments to version 2.1.5.
Relevance: supporting · Type: action
Confidence100%
Defiant advises administrators to check server access logs for requests to the affected endpoint.
Defiant, WordPress security firm
Relevance: primary · Type: quote
Confidence100%
"If you are running a vulnerable version of Gravity SMTP and have configured any third-party email integrations (such as Amazon SES, Google, Mailjet, Resend, or Zoho), you should assume the associated API keys, secrets, and OAuth tokens may have been exposed."
Defiant, WordPress security firm
Relevance: supporting · Type: quote
Confidence100%
"We strongly recommend rotating these credentials after updating the plugin."
Relevance: supporting · Type: background
Confidence100%
The Gravity SMTP plugin is active on 100,000 sites.
Relevance: supporting · Type: event
Confidence100%
Version 2.1.5 of the Gravity SMTP plugin was released on March 17.
Relevance: primary · Type: action
Confidence100%
Defiant's Wordfence firewall has blocked more than 17 million attempts against protected customers.
Relevance: supporting · Type: background
Confidence100%
The Gravity SMTP plugin’s ‘permission_callback’ always returns ‘true.’
Relevance: supporting · Type: background
Confidence100%
Unauthenticated GET requests to the vulnerable endpoint receive a comprehensive JSON “System Report” generated by the plugin.
Wordfence researchers, security researchers
Relevance: primary · Type: quote
Confidence100%
"The exposure of live third-party API credentials means an attacker could abuse the site’s connected email services, while the detailed system report significantly lowers the effort required to plan further attacks against the site."
Relevance: primary · Type: event
Confidence100%
Wordfence says exploitation activity spiked on June 7, with 4 million requests being blocked that day.
Relevance: supporting · Type: background
Confidence100%
A key indicator of compromise is requests to ‘/wp-json/gravitysmtp/v1/tests/mock-data’ found in web server access logs, particularly those including the ‘?page=gravitysmtp-settings’ query parameter.
forum Comments (0)
No comments yet. Be the first to comment.