Close Menu
    What's Hot

    Super League: Champions Hull KR beat Leigh Leopards while Wakefield Trinity rout Hull FC | Rugby League News

    What Fox and Roku aren’t telling us yet

    Opinion | Creature From the Green Lagoon

    Facebook X (Twitter) Instagram
    Trending
    • Super League: Champions Hull KR beat Leigh Leopards while Wakefield Trinity rout Hull FC | Rugby League News
    • What Fox and Roku aren’t telling us yet
    • Opinion | Creature From the Green Lagoon
    • ITWO: Reduce Small-Cap Risk With Monthly Income (BATS:ITWO)
    • Scotland at World Cup: Steve Clarke’s side cannot concede early again against Brazil, says Kris Boyd | Football News
    • 2026 World Cup picks, odds, predictions: Best bets for Germany-Ivory Coast, Japan-Tunisia on Saturday
    • Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
    • Opinion | We Need to Keep Funding Weird Science
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

    adminBy adminJune 20, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 20, 2026Vulnerability / Web Security

    Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

    Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that’s installed on about 100,000 sites.

    The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data, such as configuration data, API keys, secrets, and OAuth tokens configured for the plugin’s email integrations.

    “This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor to access it,” Wordfence said.

    Cybersecurity

    “When the ?page=gravitysmtp-settings query parameter is appended, the plugin’s register_connector_data() method populates internal connector data, causing the endpoint to return approximately 365 KB of JSON containing the full System Report.”

    As a result, an unauthenticated attacker can weaponize this issue to retrieve a wide range of information, including –

    • PHP version
    • Loaded extensions
    • Web server version
    • Document root path
    • Database server type and version
    • WordPress version
    • All active plugins with versions
    • Active theme
    • WordPress configuration details
    • Database table names
    • API keys/tokens configured in the plugin, such as Amazon SES, Google, Mailjet, Resend, and Zoho

    Attackers could then leverage this exposure to harvest credentials that could be abused to send email on behalf of the site, as well as glean extensive details of the site’s software stack, which could act as a foundation for follow-on attacks.

    “As with all sensitive information exposure vulnerabilities, the impact depends on what data is exposed,” Wordfence added. “In this case, the exposure of live third-party API credentials means an attacker could abuse the site’s connected email services, while the detailed system report significantly lowers the effort required to plan further attacks against the site.”

    A patch for the vulnerability has been released in version 2.1.5 of the plugin. Bad actors have already pounced on the defect by sending unauthenticated HTTP GET requests to the vulnerable REST API endpoint with the “?page=gravitysmtp-settings” query parameter, causing the server to return valuable information about the site without requiring any authentication.

    Cybersecurity

    Wordfence has blocked more than 17 million exploit attempts targeting CVE-2026-4020 to date, with initial activity commencing at the start of May 2026 before spiking up dramatically around June 6, 2026, touching a high of over 4,000,000 requests a day later. The exploit efforts have originated from the following IP addresses –

    • 45.148.10.95
    • 193.32.162.60
    • 176.65.148.139
    • 173.199.90.188
    • 45.148.10.120
    • 185.8.107.155
    • 185.8.106.37
    • 185.8.106.92
    • 185.8.106.145
    • 176.65.148.30

    Site owners running a vulnerable version of the Gravity SMTP plugin and have configured third-party email integrations should assume compromise, and rotate the credentials after updating the plugin to the latest version as soon as possible. It’s also advised to review server log files for requests originating from the aforementioned IP addresses for any suspicious requests to the API endpoint.

    API bug Exploit expose Gravity hackers Keys Plugin SMTP Wordpress
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleOpinion | We Need to Keep Funding Weird Science
    Next Article 2026 World Cup picks, odds, predictions: Best bets for Germany-Ivory Coast, Japan-Tunisia on Saturday
    admin
    • Website

    Related Posts

    CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices

    June 19, 2026

    The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

    June 19, 2026

    Unpatchable ‘usbliter8’ Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

    June 19, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Super League: Champions Hull KR beat Leigh Leopards while Wakefield Trinity rout Hull FC | Rugby League News

    What Fox and Roku aren’t telling us yet

    Opinion | Creature From the Green Lagoon

    ITWO: Reduce Small-Cap Risk With Monthly Income (BATS:ITWO)

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by