Hackers exploit Gravity SMTP WordPress plugin flaw CVE-2026-4020 to expose API keys and email credentials

Hackers are actively exploiting a flaw in the Gravity SMTP WordPress plugin that can expose sensitive data from affected websites. The bug, CVE-2026-4020, affects Gravity SMTP 2.1.4 and earlier and was fixed in 2.1.5 on March 17. An unauthenticated REST API endpoint can return a JSON system report containing API keys, OAuth tokens, third-party email service credentials, WordPress configuration details, and server and database information. Wordfence says it blocked more than 17 million exploit attempts, with activity spiking on June 7.
Why it matters: Site owners can have email-service secrets and internal configuration exposed without an attacker needing to log in, which can enable account abuse and follow-on compromise. Organizations using Gravity SMTP should update to 2.1.5 immediately and review logs for requests to /wp-json/gravitysmtp/v1/tests/mock-data.

Sources

Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
Ionut Arghire 2026.06.22 96% relevant
This source directly updates the same event by adding that exploitation has surged in June, Defiant has blocked more than 17 million exploit attempts, and exposed data can include API keys, secrets, OAuth tokens, server details, and WordPress configuration data from Gravity SMTP versions before 2.1.5.
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
info@thehackernews.com (The Hacker News) 2026.06.20 99% relevant
This article appears to cover the same underlying event: active exploitation of the Gravity SMTP WordPress plugin flaw that exposes API keys and email credentials on vulnerable sites.
Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
Bill Toulas 2026.06.19 100% relevant
This article establishes a distinct story about active exploitation of CVE-2026-4020 in the Gravity SMTP plugin, separate from other tracked WordPress plugin exploitation cases.
← Back to all stories