Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

    September 12, 2026

    Aging Congress Is Completely Ill-Equipped to Regulate AI, or Seemingly Even Understand It

    September 12, 2026

    Samsung Galaxy S26 FE’s India price leaks

    September 12, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
    Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
    Cybersecurity

    Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data

    The Tech GuyBy The Tech GuyJune 22, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Threat actors are exploiting a medium-severity vulnerability in the Gravity SMTP WordPress plugin to steal complete system details, Defiant warns.

    Advertisement

    Gravity SMTP for WordPress is an email deliverability plugin that integrates with multiple SMTP providers and API-based services to allow admins to send and track emails directly from their websites.

    All plugin iterations before version 2.1.5 are affected by a sensitive information exposure vulnerability tracked as CVE-2026-4020 (CVSS score of 5.3) that has been exploited in the wild since early May.

    The issue impacts a REST API endpoint that unconditionally returns true, thus becoming accessible to any unauthenticated user. If a specific parameter is appended to a query, the endpoint returns internal connector data in JSON format.

    The data contains the full system report, including configuration data such as PHP and WordPress version, loaded extensions, web server details, document root path, database details, active plugins and theme, WordPress configuration details, and configured API keys/tokens.

    According to Defiant, the bug exists because the impacted REST API endpoint, registered within a shared library providing a configuration collection system, does not perform authentication or capability checks.

    Advertisement. Scroll to continue reading.

    “This makes it possible for unauthenticated attackers to harvest credentials that could be used to send email on behalf of the site, as well as to gather detailed reconnaissance about the site’s software stack that can be leveraged to identify and target other vulnerabilities,” Defiant explains.

    The WordPress security firm has observed in-the-wild exploitation of the security defect since early May. Attackers have been sending unauthenticated GET requests to the vulnerable endpoint to retrieve the full System Report JSON object.

    In June, Defiant has observed a surge in attacks targeting CVE-2026-4020. To date, the company has blocked over 17 million exploit attempts.

    Site owners and administrators are advised to update their Gravity SMTP deployments to version 2.1.5 as soon as possible and to check server access logs for requests to the affected endpoint, as the in-the-wild exploitation does not leave other obvious traces.

    “If you are running a vulnerable version of Gravity SMTP and have configured any third-party email integrations (such as Amazon SES, Google, Mailjet, Resend, or Zoho), you should assume the associated API keys, secrets, and OAuth tokens may have been exposed. We strongly recommend rotating these credentials after updating the plugin,” Defiant notes.

    Related: Majority of Internet-Accessible REDCap Servers Outdated

    Related: 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown

    Related: Joomla, LiteSpeed Vulnerabilities Exploited in Attacks

    Related: No Exploits Required

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

    September 12, 2026

    BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

    September 12, 2026

    GitLab Vulnerability Exploited One Day After Disclosure

    September 12, 2026

    Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

    September 12, 2026

    Phishing Research Challenges Conventional Security Awareness Testing

    September 11, 2026

    In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

    September 11, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

    September 12, 2026

    Aging Congress Is Completely Ill-Equipped to Regulate AI, or Seemingly Even Understand It

    September 12, 2026

    Samsung Galaxy S26 FE’s India price leaks

    September 12, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.