ctipilot.ch
← Back to Weekly 2026-W26
NOTABLECVE-2026-4020exploitedvulnerability

CVE-2026-4020 — Gravity SMTP WordPress plugin: unauthenticated credential dump, mass-exploited

discovered 2026-06-22 00:14 UTCrun 2026-W25-0aacfe652 sourcesmulti-source

An unauthenticated information-disclosure flaw in the Gravity SMTP plugin (all versions through 2.1.4) lets an attacker dump the configured email-connector credentials (SMTP, SendGrid, Mailgun and similar API keys), and it is being mass-exploited (GitHub Advisory GHSA-jxfc-8wcq-xxcg; daily 06-21). Stolen mail-sending credentials enable downstream phishing from a trusted domain. Update the plugin and rotate every credential stored in it.

An unauthenticated information-disclosure flaw in the Gravity SMTP plugin (all versions through 2.1.4) lets an attacker dump the configured email-connector credentials (SMTP, SendGrid, Mailgun and similar API keys), and it is being mass-exploited (GitHub Advisory GHSA-jxfc-8wcq-xxcg; daily 06-21).

ctipilot v2 brief (migrated)
PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.