Logo
News Ababil
Explore
Global Intel (English)
Global Intel (English)VOICE
Bengali (বাংলা)
Spanish (Español)VOICE
French (Français)VOICE
German (Deutsch)
Arabic (العربية)
Hindi (हिन्दी)VOICE
Chinese (中文)
Japanese (日本語)
Russian (Русский)
SYS_NODE: ONLINE // Cyber Security

Gravity SMTP Vulnerability Exposes API Keys on 100,000 WordPress Sites

DECRYPTED BY: Kaelen Frost | TIMESTAMP: 2026-06-21 T 09:06:00 Z | [ 1 MIN READ ]
Gravity SMTP Vulnerability Exposes API Keys on 100,000 WordPress Sites
1 Min Read
Share

Threat actors are exploiting the Gravity SMTP vulnerability (CVE-2026-4020) to siphon API keys from roughly ↑ 100,000 WordPress installations.

Gravity SMTP vulnerability details

The flaw, rated ↓ 5.3 on the CVSS scale, is an information‑disclosure issue that permits unauthenticated requests to retrieve configuration files, API secrets and OAuth tokens.

Attack vector and impact

By sending a crafted HTTP request to the plugin’s endpoint, attackers can pull the wp_options entry that stores the SMTP service credentials, effectively compromising any integrated email service.

“The ease of exploitation makes this one of the most urgent patches of the year,” said a senior analyst at Bloomberg.

WordPress sites that have not applied the December 2025 update remain exposed, and security firms advise immediate remediation and rotation of all exposed keys.

For broader context on WordPress plugin attacks, see Reuters.

Intel provided by: Kaelen Frost
Lead Cybersecurity Analyst
Global Data Feed

More from this Intel

Vectra AI Unveils Ascent to Counter AI-Driven Attacks

Vectra AI Unveils Ascent to Counter AI-Driven Attacks

Sep 20, 2026
Google Infiltrated TeamPCP: Inside the Undercover Operation that Stopped a Massive Supply‑Chain Attack

Google Infiltrated TeamPCP: Inside the Undercover Operation that Stopped a...

Sep 20, 2026
Gyazo data breach leaks 23.6 million accounts – massive server flaw exposed

Gyazo data breach leaks 23.6 million accounts – massive server...

Sep 19, 2026
Microsoft security patches shatter record with 974 fixes in September

Microsoft security patches shatter record with 974 fixes in September

Sep 19, 2026
Linux kernel exploit exposes four local‑root flaws, patches urged

Linux kernel exploit exposes four local‑root flaws, patches urged

Sep 18, 2026
Microsoft patches bug behind ‘Defender Antivirus turned off alerts’

Microsoft patches bug behind ‘Defender Antivirus turned off alerts’

Sep 18, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.