Interestana
Home/News/Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

Hackers are exploiting a security vulnerability in the Gravity SMTP WordPress plugin, which is installed on approximately 100,000 websites. The flaw, identified as CVE-2026-4020 with a CVSS score of 5.3, is a medium-severity information disclosure issue. This vulnerability allows unauthenticated attackers to access and extract sensitive information, including configuration data, API keys, secrets, and OAuth tokens. The Gravity SMTP plugin facilitates the sending of emails from WordPress sites. The vulnerability was patched by the plugin developers, but active exploitation indicates that many sites have not yet updated their plugin versions. The exposure of API keys and secrets can lead to further security breaches, potentially compromising connected services and user data. WordPress security researchers have urged site administrators to update the Gravity SMTP plugin to the latest version immediately to mitigate the risk of data exfiltration.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next