Gravity SMTP, a popular WordPress plugin installed on around 100,000 websites, is at the center of a malicious campaign. The vulnerability , CVE-2026-4020, with a CVSS score of 5.3, allows unauthorized attackers to exfiltrate sensitive data — including API keys, OAuth tokens , and full configuration data — without requiring any authentication. Wordfence has already blocked more than 17 million exploit attempts, peaking at 4 million requests in a single dayon June 7, 2026.

The vulnerability was found in the REST API endpoint /wp-json/gravitysmtp/v1/tests/mock-data, which has a permission_callback that always returns true — meaning it allows access to any visitor without authentication. When the parameter ?page=gravitysmtp-settings, the endpoint returns a ~365 KB JSON file containing the full “System Report” of the website. This means that an attacker can perform a simple HTTP GET request and gain access to highly sensitive information.
The exposed data includes database server type and version, table names, WordPress configuration details , all active plugins and their versions, as well as API keys and tokens for services such as Amazon SES , Google , Mailjet , Resend , and Zoho . In addition, PHP versions, web server information, loaded extensions, and active theme details are exposed . This dataset provides a complete “map” of the website for an attacker.
See also: Vulnerability in Kirki Plugin puts WordPress sites at risk
Gravity SMTP CVE-2026-4020: How the Exploit Campaign Evolved
The Gravity SMTP vulnerability was publicly disclosed on March 30-31, 2026 , while RocketGenius — the plugin's developer — had already released a fix in version 2.1.5 on March 17, 2026. Versions 2.1.4 and older remain vulnerable. The exploit began in May 2026 , with CrowdSec recording the first attacks on May 27, 2026 , and identifying 412 different IP addresses associated with the attack by June 1, 2026. This suggests that this is not an isolated attack, but a widespread automated campaign.
According to CrowdSec, the exploitation activity quickly shifted from targeted detection to “background noise” — that is, fully automated mass scanning. Check Point also issued an alert and activated protective mechanisms for its customers, reflecting the broader defensive reaction seen when WordPress plugin vulnerabilities begin to be exploited en masse. According to The Hacker News, Wordfence notes that the initial activity began in early May and peaked dramatically around June 6, 2026.
The risk of exposing API keys and SMTP credentials is very specific: attackers can use the stolen credentials to send emails on behalf of the victim website through services like Amazon SES or Google. This paves the way for spam and phishing that appear legitimate, as they come from trusted infrastructure. At the same time, revealing the detailed software stack of the website significantly reduces the effort required to plan further attacks.
See also: WordPress: Hackers exploit Burst Statistics vulnerability
What WordPress site administrators should do with Gravity SMTP
Site administrators using Gravity SMTP version 2.1.4 or earlier should immediately upgrade to version 2.1.5 or later. If the site had third-party email integrations configured, credentials should be considered compromised. Immediate refresh is required, including all API keys , secrets , and OAuth tokens . Additionally, it is recommended to check the server logs for requests to the /wp-json/gravitysmtp/v1/tests/mock-data endpoint , especially those containing the parameter ?page=gravitysmtp-settings .

For sites that cannot be upgraded immediately, it is recommended to place a WAF (Web Application Firewall) or IPS rule in front of the site to block access to the vulnerable endpoint. Both Wordfence and Check Point have already deployed active protection solutions for their customers. Finally, a full audit for any further compromise is recommended, as the exposed configuration data may have helped the attackers identify other vulnerabilities in the WordPress stack.
See also: Vulnerability in WordPress Post SMTP plugin – 400,000 sites at risk
The Gravity SMTP is a prime example of a recurring pattern in the WordPress: moderate severity vulnerabilities that expose credentials or metadata can become highly valuable to attackers, leading to massive automated exploitation campaigns. With 17 million blocked attempts and hundreds of IPs, the message is clear: upgrading and renewing credentials immediately is not just a recommendation — it’s an urgent necessity.
What does it mean for Greece?
Greece has a huge WordPress base in SMEs/eshops/media. Loss of control of the email channel leads to phishing "as if it came from you", domain blacklisting and financial loss.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
