Logo
News Ababil
Explore
SYS_NODE: ONLINE // Cyber Security

Gravity SMTP Vulnerability Exposes API Keys on 100,000 WordPress Sites

DECRYPTED BY: Kaelen Frost | TIMESTAMP: 2026-06-21 T 09:06:00 Z | [ 1 MIN READ ]
Gravity SMTP Vulnerability Exposes API Keys on 100,000 WordPress Sites
1 Min Read
Share

Threat actors are exploiting the Gravity SMTP vulnerability (CVE-2026-4020) to siphon API keys from roughly ↑ 100,000 WordPress installations.

Gravity SMTP vulnerability details

The flaw, rated ↓ 5.3 on the CVSS scale, is an information‑disclosure issue that permits unauthenticated requests to retrieve configuration files, API secrets and OAuth tokens.

Attack vector and impact

By sending a crafted HTTP request to the plugin’s endpoint, attackers can pull the wp_options entry that stores the SMTP service credentials, effectively compromising any integrated email service.

“The ease of exploitation makes this one of the most urgent patches of the year,” said a senior analyst at Bloomberg.

WordPress sites that have not applied the December 2025 update remain exposed, and security firms advise immediate remediation and rotation of all exposed keys.

For broader context on WordPress plugin attacks, see Reuters.

Intel provided by: Kaelen Frost
Lead Cybersecurity Analyst
Global Data Feed

More from this Intel

Rogue AI Agents Resurface: New Wave of Server Intrusions Threatens Global Cyber Defenses

Rogue AI Agents Resurface: New Wave of Server Intrusions Threatens...

Aug 05, 2026
ScreenConnect RMM Takeover Playbook: How Threat Actors Hijack Networks with Rotating Payloads

ScreenConnect RMM Takeover Playbook: How Threat Actors Hijack Networks with...

Aug 05, 2026
N-central auth bypass flaw fuels rapid cyber campaigns, N-able warns of active exploitation

N-central auth bypass flaw fuels rapid cyber campaigns, N-able warns...

Aug 04, 2026
Malwarebytes Free Antivirus Program Expands to US College Campuses

Malwarebytes Free Antivirus Program Expands to US College Campuses

Aug 04, 2026
Anthropic model cyberattack exposes AI evaluation flaws as three firms compromised

Anthropic model cyberattack exposes AI evaluation flaws as three firms...

Aug 01, 2026
Device Code Phishing: 6 Drivers Behind 2026’s Fastest‑Growing Cyber Threat

Device Code Phishing: 6 Drivers Behind 2026’s Fastest‑Growing Cyber Threat

Jul 31, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.