Logo
News Ababil
Explore
SYS_NODE: ONLINE // Cyber Security

Gravity SMTP Vulnerability Exposes API Keys on 100,000 WordPress Sites

DECRYPTED BY: Kaelen Frost | TIMESTAMP: 2026-06-21 T 09:06:00 Z | [ 1 MIN READ ]
Gravity SMTP Vulnerability Exposes API Keys on 100,000 WordPress Sites
1 Min Read
Share

Threat actors are exploiting the Gravity SMTP vulnerability (CVE-2026-4020) to siphon API keys from roughly ↑ 100,000 WordPress installations.

Gravity SMTP vulnerability details

The flaw, rated ↓ 5.3 on the CVSS scale, is an information‑disclosure issue that permits unauthenticated requests to retrieve configuration files, API secrets and OAuth tokens.

Attack vector and impact

By sending a crafted HTTP request to the plugin’s endpoint, attackers can pull the wp_options entry that stores the SMTP service credentials, effectively compromising any integrated email service.

“The ease of exploitation makes this one of the most urgent patches of the year,” said a senior analyst at Bloomberg.

WordPress sites that have not applied the December 2025 update remain exposed, and security firms advise immediate remediation and rotation of all exposed keys.

For broader context on WordPress plugin attacks, see Reuters.

Intel provided by: Kaelen Frost
Lead Cybersecurity Analyst
Global Data Feed

More from this Intel

News

Shield Your Devices: The Best Antivirus Software 2026 Reviewed

Aug 13, 2026
Hackers Exploit Adobe Commerce Vulnerability to Hijack Customer Accounts

Hackers Exploit Adobe Commerce Vulnerability to Hijack Customer Accounts

Aug 13, 2026
StormEncryptor ransomware Emerges: China‑Linked Hackers Target N‑central Vulnerability

StormEncryptor ransomware Emerges: China‑Linked Hackers Target N‑central Vulnerability

Aug 11, 2026
Water System Attacks Surge Across U.S., Iran Suspected

Water System Attacks Surge Across U.S., Iran Suspected

Aug 11, 2026
Evolving Threat: StormEncryptor ransomware Targets Mid‑Size Firms After Medusa Split

Evolving Threat: StormEncryptor ransomware Targets Mid‑Size Firms After Medusa Split

Aug 11, 2026
GhostJacking Reveals Critical Gaps in AI Identity Governance

GhostJacking Reveals Critical Gaps in AI Identity Governance

Aug 11, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.