Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Barbara Mazzolai Is Cultivating Sustainability Robotics

    September 23, 2026

    Three-Year-Old Boy’s Metastatic Cancer Disappears After Two Shots of Experimental Cell Therapy

    September 22, 2026

    How to Claim Your Cut of Apple’s $250 Million Siri Settlement

    September 22, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Barbara Mazzolai Is Cultivating Sustainability Robotics
    • Three-Year-Old Boy’s Metastatic Cancer Disappears After Two Shots of Experimental Cell Therapy
    • How to Claim Your Cut of Apple’s $250 Million Siri Settlement
    • The Download: why AI’s latest breakthroughs and fears may be more hype than reality
    • Spain’s Astronaut Pedro Duque Is IEEE Honorary Member
    • Can AI reason without words? A small model puts the idea to the test
    • Rabbit Is Back, This Time With an AI Agent App
    • Roundtables: The Deadly Failures of The Virtual Border Wall
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
    Cybersecurity

    Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin

    kirklandc008@gmail.comBy kirklandc008@gmail.comJune 19, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    WP Maps Pro bug exploited to create admin accounts on WordPress sites
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites.

    The flaw is tracked as CVE-2026-4020 and received a medium severity rating. It affects all versions of the plugin from 2.1.4 and older and has been addressed in version 2.1.5, released on March 17.

    WordPress security company Defiant is warning that hackers are actively exploiting the vulnerability. The company’s Wordfence firewall has blocked more than 17 million attempts against protected customers.

    The issue stems from an exposed REST API endpoint in Gravity SMTP, whose ‘permission_callback’ always returns ‘true,’ allowing unauthenticated GET requests to receive a comprehensive JSON “System Report” generated by the plugin. The exposed information may contain:

    • API keys, secrets, and OAuth tokens for configured email integrations
    • Credentials for third-party email services, including Amazon SES, Google, Mailjet, Resend, and Zoho
    • WordPress configuration details, including installed plugins, themes, and software versions
    • Server and PHP environment information
    • Database configuration details, including server version and table names

    Despite its medium-severity rating, the CVE-2026-4020 vulnerability can be exploited without authentication, and the exposed information can be used to steal email service credentials.

    This allows an attacker to impersonate the victim to third parties and also to gain detailed information about the site’s software stack and the potential vulnerabilities present.

    “The exposure of live third-party API credentials means an attacker could abuse the site’s connected email services, while the detailed system report significantly lowers the effort required to plan further attacks against the site,” Wordfence researchers warn.

    Wordfence says exploitation activity spiked on June 7, with 4 million requests being blocked that day. Similar activity was recorded for several days afterward.

    Exploitation volume
    Source: Wordfence

    The security firm listed the most prolific source IP addresses for exploit requests, which website administrators should add to their blocklists.

    A key indicator of compromise is requests to ‘/wp-json/gravitysmtp/v1/tests/mock-data’ found in web server access logs, particularly those including the ‘?page=gravitysmtp-settings’ query parameter.

    Yesterday, the company issued a separate advisory about a critical, unauthenticated, arbitrary file-deletion flaw in the Avada Builder WordPress plugin, used on one million sites.

    This vulnerability is identified as CVE-2026-8713 and allows attackers to delete arbitrary files on the server through a path traversal flaw, provided a published Avada form is configured to save submissions to the database.

    Deleting critical files, such as wp-config.php, can revert the site to its initial setup state, potentially leading to a full site takeover and remote code execution.

    The issue was fixed in version 3.15.4, which is the recommended upgrade target for website administrators. No active exploitation of CVE-2026-8713 has been observed yet, but this is a good candidate, so quick action is advised.

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    bug Disclosure exploit gravity hackers info plugin SMTP WordPress
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

    August 11, 2026

    Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting

    July 31, 2026

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Barbara Mazzolai Is Cultivating Sustainability Robotics
    • Three-Year-Old Boy’s Metastatic Cancer Disappears After Two Shots of Experimental Cell Therapy
    • How to Claim Your Cut of Apple’s $250 Million Siri Settlement
    • The Download: why AI’s latest breakthroughs and fears may be more hype than reality
    • Spain’s Astronaut Pedro Duque Is IEEE Honorary Member

    Barbara Mazzolai Is Cultivating Sustainability Robotics

    September 23, 2026

    Three-Year-Old Boy’s Metastatic Cancer Disappears After Two Shots of Experimental Cell Therapy

    September 22, 2026

    How to Claim Your Cut of Apple’s $250 Million Siri Settlement

    September 22, 2026

    The Download: why AI’s latest breakthroughs and fears may be more hype than reality

    September 22, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.