Gravity SMTP (CVE-2026-4020): API keys exposed — update to 2.1.5

Colleagues, note: a vulnerability was found in the Gravity SMTP (WordPress) plugin allowing unauthenticated requests to retrieve system reports and API keys.
What happened:
Wordfence found that the REST endpoint /wp-json/gravitysmtp/v1/tests/mock-data with ?page=gravitysmtp-settings returns ~365 KB JSON because permission_callback always returns true — CVE-2026-4020.
Risks:
Exposure of credentials (Amazon SES, Google, Mailjet, etc.), stack and plugin data — enabling forged mail from the site and follow-on attacks.
Actions:
Update to 2.1.5, rotate keys and review logs for requests to the endpoint.
Why it matters:
Live third-party credentials are a direct abuse vector.
Have you checked your sites and rotated keys?
#cybersecurity #WordPress #infosec #vulnerabilities

