• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

Admin by Admin
June 21, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananJun 20, 2026Vulnerability / Net Safety

Menace actors are exploiting a just lately patched safety flaw impacting Gravity SMTP, a WordPress plugin that is put in on about 100,000 websites.

The vulnerability, tracked as CVE-2026-4020 (CVSS rating: 5.3), is a medium-severity data disclosure flaw that may enable unauthenticated attackers to extract delicate knowledge, comparable to configuration knowledge, API keys, secrets and techniques, and OAuth tokens configured for the plugin’s electronic mail integrations.

“This is because of a REST API endpoint registered at /wp-json/gravitysmtp/v1/checks/mock-data with a permission_callback that unconditionally returns true, permitting any unauthenticated customer to entry it,” Wordfence stated.

“When the ?web page=gravitysmtp-settings question parameter is appended, the plugin’s register_connector_data() technique populates inner connector knowledge, inflicting the endpoint to return roughly 365 KB of JSON containing the complete System Report.”

In consequence, an unauthenticated attacker can weaponize this concern to retrieve a variety of knowledge, together with –

  • PHP model
  • Loaded extensions
  • Net server model
  • Doc root path
  • Database server sort and model
  • WordPress model
  • All energetic plugins with variations
  • Lively theme
  • WordPress configuration particulars
  • Database desk names
  • API keys/tokens configured within the plugin, comparable to Amazon SES, Google, Mailjet, Resend, and Zoho

Attackers may then leverage this publicity to reap credentials that could possibly be abused to ship electronic mail on behalf of the location, in addition to glean in depth particulars of the location’s software program stack, which may act as a basis for follow-on assaults.

“As with all delicate data publicity vulnerabilities, the impression is determined by what knowledge is uncovered,” Wordfence added. “On this case, the publicity of stay third-party API credentials means an attacker may abuse the location’s related electronic mail companies, whereas the detailed system report considerably lowers the trouble required to plan additional assaults in opposition to the location.”

A patch for the vulnerability has been launched in model 2.1.5 of the plugin. Dangerous actors have already pounced on the defect by sending unauthenticated HTTP GET requests to the weak REST API endpoint with the “?web page=gravitysmtp-settings” question parameter, inflicting the server to return useful details about the location with out requiring any authentication.


Wordfence has blocked greater than 17 million exploit makes an attempt concentrating on CVE-2026-4020 up to now, with preliminary exercise commencing firstly of Might 2026 earlier than spiking up dramatically round June 6, 2026, touching a excessive of over 4,000,000 requests a day later. The exploit efforts have originated from the next IP addresses –

  • 45.148.10.95
  • 193.32.162.60
  • 176.65.148.139
  • 173.199.90.188
  • 45.148.10.120
  • 185.8.107.155
  • 185.8.106.37
  • 185.8.106.92
  • 185.8.106.145
  • 176.65.148.30

Web site house owners operating a weak model of the Gravity SMTP plugin and have configured third-party electronic mail integrations ought to assume compromise, and rotate the credentials after updating the plugin to the newest model as quickly as attainable. It is also suggested to evaluate server log information for requests originating from the aforementioned IP addresses for any suspicious requests to the API endpoint.

Tags: APIbugExploitexposeGravityhackerskeysPluginSMTPWordPress
Admin

Admin

Next Post
Summer season Blackout To-Do Record: 9 Issues to Hold Everybody Cool and Protected

Summer season Blackout To-Do Record: 9 Issues to Hold Everybody Cool and Protected

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

You’ll at all times keep in mind this because the day you lastly caught FamousSparrow

You’ll at all times keep in mind this because the day you lastly caught FamousSparrow

June 18, 2025
After one 12 months, D&D 2024 nonetheless doesn’t know what it desires to be

After one 12 months, D&D 2024 nonetheless doesn’t know what it desires to be

December 24, 2025

Trending.

AI & data-driven Starbucks – Deep Brew

AI & data-driven Starbucks – Deep Brew

May 18, 2026
Meet FreeToken: An Edge-Native MoE Serving Engine that Runs 753B GLM-5.2 on a Single Workstation GPU

Meet FreeToken: An Edge-Native MoE Serving Engine that Runs 753B GLM-5.2 on a Single Workstation GPU

August 23, 2026
The Full Information to EcoGPT

The Full Information to EcoGPT

June 6, 2026
Attackers Exploit MCP RCE, Blind Immediate Injection and Reminiscence Credential Theft Towards AI Infrastructure

Attackers Exploit MCP RCE, Blind Immediate Injection and Reminiscence Credential Theft Towards AI Infrastructure

August 29, 2026
Hasbro Information Breach Uncovered Worker Private Data

Hasbro Information Breach Uncovered Worker Private Data

August 30, 2026

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

Not all AI staff assume the tech might kill everybody

Not all AI staff assume the tech might kill everybody

September 20, 2026
Claude Opus 5 Helped Researchers Take Over OpenAI Employees Accounts by way of Chained Flaws

Claude Opus 5 Helped Researchers Take Over OpenAI Employees Accounts by way of Chained Flaws

September 20, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved