VMTech
Discuss a project

Gravity SMTP (CVE-2026-4020): API keys exposed — update to 2.1.5

Gravity SMTP (CVE-2026-4020): API keys exposed — update to 2.1.5

Colleagues, note: a vulnerability was found in the Gravity SMTP (WordPress) plugin allowing unauthenticated requests to retrieve system reports and API keys.

What happened:
Wordfence found that the REST endpoint /wp-json/gravitysmtp/v1/tests/mock-data with ?page=gravitysmtp-settings returns ~365 KB JSON because permission_callback always returns true — CVE-2026-4020.

Risks:
Exposure of credentials (Amazon SES, Google, Mailjet, etc.), stack and plugin data — enabling forged mail from the site and follow-on attacks.

Actions:
Update to 2.1.5, rotate keys and review logs for requests to the endpoint.

Why it matters:
Live third-party credentials are a direct abuse vector.

Have you checked your sites and rotated keys?
#cybersecurity #WordPress #infosec #vulnerabilities

Open analytics
On the site 0 views
min read 1 20.06.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

Gravity SMTP (CVE-2026-4020): API keys exposed — update to 2.1.5

Open the post on Instagram ↗