- What: A WordPress plugin is being actively exploited for sensitive information disclosure
- Impact: Over 100,000 websites using Gravity SMTP may be at risk of exposing API keys, credentials, and server details
Vulnerability Management WordPress plugin Gravity SMTP exploited for sensitive information disclosure June 22, 2026 Share By SC Staff (Credit: Bilal Ulker – stock.adobe.com) Threat actors are actively exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, which is installed on over 100,000 websites. The flaw, tracked as CVE-2026-4020, allows attackers to gather sensitive data from affected sites, based on information published by Bleeping Computer. The vulnerability resides in an exposed REST API endpoint within the Gravity SMTP plugin. Attackers can send unauthenticated GET requests to retrieve a detailed "System Report." This report may include API keys, secrets, OAuth tokens, credentials for email services like Amazon SES and Google, WordPress configuration details, server information, and database configurations. Although rated medium severity, the unauthenticated nature of the exploit and the potential to steal email service credentials make it a significant risk. Wordfence has blocked over 17 million exploit attempts, with a notable spike on June 7. The exposed information can be used to impersonate the victim to third parties and plan further attacks. A separate advisory warns of a critical file deletion vulnerability (CVE-2026-8713) in the Avada Builder plugin, though no exploitation has been observed yet. Source: Bleeping Computer SC Staff Related Vulnerability Management Max severity Joomla Content Editor extension flaw targeted in automated attacks Laura French June 17, 2026 The flaw was added to CISA’s Known Exploited Vulnerabilities catalog with a three-day deadline. Vulnerability Management SimpleHelp vulnerability allows unauthenticated attackers to create privileged accounts SC Staff June 16, 2026 The flaw, affecting SimpleHelp versions 5.5.15 and older, and 6.0 pre-release versions, stems from improper validation of identity assertions from an OIDC identity provider. Bug Bounties AMD faces backlash over alleged bug bounty denial and changed disclosure rules SC Staff June 16, 2026 A researcher identified as Paul reportedly found a remote code execution flaw via a man-in-the-middle attack in AMD's auto-updater. Related Events Cybercast Why Mythos is the cybersecurity crisis we need Wed Jul 22 Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds