By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Hackers are exploiting a security vulnerability in the Gravity SMTP WordPress plugin, which is installed on approximately 100,000 websites. The flaw, identified as CVE-2026-4020 with a CVSS score of 5.3, is a medium-severity information disclosure issue. This vulnerability allows unauthenticated attackers to access and extract sensitive information, including configuration data, API keys, secrets, and OAuth tokens. The Gravity SMTP plugin facilitates the sending of emails from WordPress sites. The vulnerability was patched by the plugin developers, but active exploitation indicates that many sites have not yet updated their plugin versions. The exposure of API keys and secrets can lead to further security breaches, potentially compromising connected services and user data. WordPress security researchers have urged site administrators to update the Gravity SMTP plugin to the latest version immediately to mitigate the risk of data exfiltration.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.