News Ababil.
Explore
SYS_NODE: ONLINE // Cyber Security

Gravity SMTP Vulnerability Exposes API Keys on 100,000 WordPress Sites

DECRYPTED BY: Kaelen Frost | TIMESTAMP: 2026-06-21 T 09:06:00 Z | [ 1 MIN READ ]
Gravity SMTP Vulnerability Exposes API Keys on 100,000 WordPress Sites
1 Min Read
Share

Threat actors are exploiting the Gravity SMTP vulnerability (CVE-2026-4020) to siphon API keys from roughly ↑ 100,000 WordPress installations.

Gravity SMTP vulnerability details

The flaw, rated ↓ 5.3 on the CVSS scale, is an information‑disclosure issue that permits unauthenticated requests to retrieve configuration files, API secrets and OAuth tokens.

Attack vector and impact

By sending a crafted HTTP request to the plugin’s endpoint, attackers can pull the wp_options entry that stores the SMTP service credentials, effectively compromising any integrated email service.

“The ease of exploitation makes this one of the most urgent patches of the year,” said a senior analyst at Bloomberg.

WordPress sites that have not applied the December 2025 update remain exposed, and security firms advise immediate remediation and rotation of all exposed keys.

For broader context on WordPress plugin attacks, see Reuters.

Intel provided by: Kaelen Frost
Lead Cybersecurity Analyst
Global Data Feed

More from this Intel

AI Pressures Redefine How Cybersecurity Teams Operate

AI Pressures Redefine How Cybersecurity Teams Operate

Jun 21, 2026
Popa Botnet Tied to Israeli Proxy Firm NetNut Raises Global Cybersecurity Alarm

Popa Botnet Tied to Israeli Proxy Firm NetNut Raises Global...

Jun 21, 2026
Microsoft uncovers USB worm cryptocurrency threat that hijacks clipboard and runs over Tor

Microsoft uncovers USB worm cryptocurrency threat that hijacks clipboard and...

Jun 21, 2026
Novo Nordisk Leak Highlights Software Development Pipeline Risk

Novo Nordisk Leak Highlights Software Development Pipeline Risk

Jun 19, 2026
Crypto Clipper Campaign Exploits Fake Reviews, AI Narrators, and VirusTotal Comments

Crypto Clipper Campaign Exploits Fake Reviews, AI Narrators, and VirusTotal...

Jun 18, 2026
Inside The Gentlemen ransomware: Who Is Steering the Fast‑Growing RaaS Outfit?

Inside The Gentlemen ransomware: Who Is Steering the Fast‑Growing RaaS...

Jun 18, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.