Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    The Ninja AutoBarista Pro Fully Automatic Espresso Machine lets you make just about any coffee creation you can imagine

    June 23, 2026

    The free streaming app everyone ignores has a better film catalog than Netflix

    June 23, 2026

    Turning your PC into a media streamer is easy

    June 23, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
    Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
    Cybersecurity

    Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data

    The Tech GuyBy The Tech GuyJune 22, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Threat actors are exploiting a medium-severity vulnerability in the Gravity SMTP WordPress plugin to steal complete system details, Defiant warns.

    Advertisement

    Gravity SMTP for WordPress is an email deliverability plugin that integrates with multiple SMTP providers and API-based services to allow admins to send and track emails directly from their websites.

    All plugin iterations before version 2.1.5 are affected by a sensitive information exposure vulnerability tracked as CVE-2026-4020 (CVSS score of 5.3) that has been exploited in the wild since early May.

    The issue impacts a REST API endpoint that unconditionally returns true, thus becoming accessible to any unauthenticated user. If a specific parameter is appended to a query, the endpoint returns internal connector data in JSON format.

    The data contains the full system report, including configuration data such as PHP and WordPress version, loaded extensions, web server details, document root path, database details, active plugins and theme, WordPress configuration details, and configured API keys/tokens.

    According to Defiant, the bug exists because the impacted REST API endpoint, registered within a shared library providing a configuration collection system, does not perform authentication or capability checks.

    Advertisement. Scroll to continue reading.

    “This makes it possible for unauthenticated attackers to harvest credentials that could be used to send email on behalf of the site, as well as to gather detailed reconnaissance about the site’s software stack that can be leveraged to identify and target other vulnerabilities,” Defiant explains.

    The WordPress security firm has observed in-the-wild exploitation of the security defect since early May. Attackers have been sending unauthenticated GET requests to the vulnerable endpoint to retrieve the full System Report JSON object.

    In June, Defiant has observed a surge in attacks targeting CVE-2026-4020. To date, the company has blocked over 17 million exploit attempts.

    Site owners and administrators are advised to update their Gravity SMTP deployments to version 2.1.5 as soon as possible and to check server access logs for requests to the affected endpoint, as the in-the-wild exploitation does not leave other obvious traces.

    “If you are running a vulnerable version of Gravity SMTP and have configured any third-party email integrations (such as Amazon SES, Google, Mailjet, Resend, or Zoho), you should assume the associated API keys, secrets, and OAuth tokens may have been exposed. We strongly recommend rotating these credentials after updating the plugin,” Defiant notes.

    Related: Majority of Internet-Accessible REDCap Servers Outdated

    Related: 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown

    Related: Joomla, LiteSpeed Vulnerabilities Exploited in Attacks

    Related: No Exploits Required

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data

    June 22, 2026

    North Korean Hackers Blamed for Mastra NPM Supply Chain Attack

    June 22, 2026

    15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown 

    June 20, 2026

    Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC

    June 20, 2026

    French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation

    June 20, 2026

    Cybersecurity Firms Impacted by Klue Supply Chain Attack

    June 20, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 202672 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 202618 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    The Ninja AutoBarista Pro Fully Automatic Espresso Machine lets you make just about any coffee creation you can imagine

    June 23, 2026

    The free streaming app everyone ignores has a better film catalog than Netflix

    June 23, 2026

    Turning your PC into a media streamer is easy

    June 23, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.