Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    OpenAI Creates a New Framework to Disclose Bad AI Behavior

    September 17, 2026

    The Download: AI’s trillion-dollar gamble and OpenAI’s biology data bid

    September 16, 2026

    I Trained a Fly’s Brain to Generate WIRED Story Ideas

    September 16, 2026
    Facebook X (Twitter) Instagram
    Trending
    • OpenAI Creates a New Framework to Disclose Bad AI Behavior
    • The Download: AI’s trillion-dollar gamble and OpenAI’s biology data bid
    • I Trained a Fly’s Brain to Generate WIRED Story Ideas
    • Building the materials foundation for AI
    • Physical AI Safety Under Attack From Silent Backdoors
    • Meet a mouse whose brain cortex is made up of human cells
    • China Isn’t Buying Silicon Valley’s Call for an AI Slowdown
    • AI models need more data about biology, and OpenAI is paying to create it
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
    Cybersecurity

    Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data

    kirklandc008@gmail.comBy kirklandc008@gmail.comJune 22, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    WordPress vulnerability exploited
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors are exploiting a medium-severity vulnerability in the Gravity SMTP WordPress plugin to steal complete system details, Defiant warns.

    Gravity SMTP for WordPress is an email deliverability plugin that integrates with multiple SMTP providers and API-based services to allow admins to send and track emails directly from their websites.

    All plugin iterations before version 2.1.5 are affected by a sensitive information exposure vulnerability tracked as CVE-2026-4020 (CVSS score of 5.3) that has been exploited in the wild since early May.

    The issue impacts a REST API endpoint that unconditionally returns true, thus becoming accessible to any unauthenticated user. If a specific parameter is appended to a query, the endpoint returns internal connector data in JSON format.

    The data contains the full system report, including configuration data such as PHP and WordPress version, loaded extensions, web server details, document root path, database details, active plugins and theme, WordPress configuration details, and configured API keys/tokens.

    According to Defiant, the bug exists because the impacted REST API endpoint, registered within a shared library providing a configuration collection system, does not perform authentication or capability checks.

    Advertisement. Scroll to continue reading.

    “This makes it possible for unauthenticated attackers to harvest credentials that could be used to send email on behalf of the site, as well as to gather detailed reconnaissance about the site’s software stack that can be leveraged to identify and target other vulnerabilities,” Defiant explains.

    The WordPress security firm has observed in-the-wild exploitation of the security defect since early May. Attackers have been sending unauthenticated GET requests to the vulnerable endpoint to retrieve the full System Report JSON object.

    In June, Defiant has observed a surge in attacks targeting CVE-2026-4020. To date, the company has blocked over 17 million exploit attempts.

    Site owners and administrators are advised to update their Gravity SMTP deployments to version 2.1.5 as soon as possible and to check server access logs for requests to the affected endpoint, as the in-the-wild exploitation does not leave other obvious traces.

    “If you are running a vulnerable version of Gravity SMTP and have configured any third-party email integrations (such as Amazon SES, Google, Mailjet, Resend, or Zoho), you should assume the associated API keys, secrets, and OAuth tokens may have been exposed. We strongly recommend rotating these credentials after updating the plugin,” Defiant notes.

    Related: Majority of Internet-Accessible REDCap Servers Outdated

    Related: 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown

    Related: Joomla, LiteSpeed Vulnerabilities Exploited in Attacks

    Related: No Exploits Required

    attackers data exploit Flaw gravity harvest plugin SMTP Valuable WordPress
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    The Download: AI’s trillion-dollar gamble and OpenAI’s biology data bid

    September 16, 2026

    AI models need more data about biology, and OpenAI is paying to create it

    September 16, 2026

    Meta Sued Over Training Data for Its AI and Face-Recognition Systems

    September 11, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • OpenAI Creates a New Framework to Disclose Bad AI Behavior
    • The Download: AI’s trillion-dollar gamble and OpenAI’s biology data bid
    • I Trained a Fly’s Brain to Generate WIRED Story Ideas
    • Building the materials foundation for AI
    • Physical AI Safety Under Attack From Silent Backdoors

    OpenAI Creates a New Framework to Disclose Bad AI Behavior

    September 17, 2026

    The Download: AI’s trillion-dollar gamble and OpenAI’s biology data bid

    September 16, 2026

    I Trained a Fly’s Brain to Generate WIRED Story Ideas

    September 16, 2026

    Building the materials foundation for AI

    September 16, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.