Vulnerabilities

CVE-2026-4020 Exploited in Gravity SMTP WordPress Plugin

June 23, 2026 04:18 · 10 min read
CVE-2026-4020 Exploited in Gravity SMTP WordPress Plugin

Gravity SMTP WordPress Plugin Vulnerability Exploited by Hackers

Threat actors are actively exploiting a recently discovered vulnerability in the Gravity SMTP WordPress plugin, which is currently active on over 100,000 sites. The vulnerability, tracked as CVE-2026-4020, has been given a medium severity rating and affects all versions of the plugin from 2.1.4 and older.

The issue was addressed in version 2.1.5, released on March 17, but hackers have already begun exploiting the flaw. According to WordPress security company Defiant, their Wordfence firewall has blocked over 17 million attempts against protected customers.

Vulnerability Details

The vulnerability stems from an exposed REST API endpoint in Gravity SMTP, whose ‘permission_callback’ always returns ‘true,’ allowing unauthenticated GET requests to receive a comprehensive JSON “System Report” generated by the plugin. This exposed information may contain sensitive data such as API keys, secrets, and OAuth tokens for configured email integrations, as well as credentials for third-party email services like Amazon SES, Google, Mailjet, Resend, and Zoho.

Additionally, the exposed information may include WordPress configuration details, such as installed plugins, themes, and software versions, as well as server and PHP environment information. Database configuration details, including server version and table names, may also be exposed.

Exploitation and Impact

Despite its medium-severity rating, the CVE-2026-4020 vulnerability can be exploited without authentication, and the exposed information can be used to steal email service credentials. This allows an attacker to impersonate the victim to third parties and also to gain detailed information about the site’s software stack and the potential vulnerabilities present.

“The exposure of live third-party API credentials means an attacker could abuse the site’s connected email services, while the detailed system report significantly lowers the effort required to plan further attacks against the site,” Wordfence researchers warn.

Exploitation activity spiked on June 7, with 4 million requests being blocked that day, and similar activity was recorded for several days afterward. Defiant has listed the most prolific source IP addresses for exploit requests, which website administrators should add to their blocklists.

Indicators of Compromise

A key indicator of compromise is requests to ‘/wp-json/gravitysmtp/v1/tests/mock-data’ found in web server access logs, particularly those including the ‘?page=gravitysmtp-settings’ query parameter.

Related Vulnerability in Avada Builder Plugin

Defiant also issued a separate advisory about a critical, unauthenticated, arbitrary file-deletion flaw in the Avada Builder WordPress plugin, used on one million sites. This vulnerability is identified as CVE-2026-8713 and allows attackers to delete arbitrary files on the server through a path traversal flaw, provided a published Avada form is configured to save submissions to the database.

Deleting critical files, such as wp-config.php, can revert the site to its initial setup state, potentially leading to a full site takeover and remote code execution. The issue was fixed in version 3.15.4, which is the recommended upgrade target for website administrators. No active exploitation of CVE-2026-8713 has been observed yet, but this is a good candidate, so quick action is advised.

Conclusion

Website administrators using the Gravity SMTP or Avada Builder WordPress plugins should take immediate action to update to the latest versions and monitor their sites for signs of exploitation. The exposure of sensitive information and potential for further attacks make these vulnerabilities a high priority for remediation.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free