National Cyber Warfare Foundation (NCWF)

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys


0 user ratings
2026-06-20 10:17:06
milo
Red Team (CNA) , Attacks
Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000 sites.

The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data, such as configuration data, API keys, secrets, and OAuth tokens



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/06/hackers-exploit-gravity-smtp-wordpress.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)
Attacks



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.