Hackers Exploit Gravity SMTP WordPress Plugin Vulnerability to Access API Keys

Threat actors are actively exploiting CVE-2026-4020, a recently patched medium-severity information disclosure vulnerability in the Gravity SMTP WordPress plugin. This flaw can be leveraged by unauthenticated attackers to access sensitive data including API keys, configuration details, and OAuth tokens, impacting approximately 100,000 WordPress sites.
What happened
Security researchers have identified active exploitation of a vulnerability in the Gravity SMTP WordPress plugin, tracked as CVE-2026-4020. The vulnerability is categorized as a medium-severity information disclosure flaw, allowing unauthenticated attackers to retrieve sensitive internal data. The plugin currently has around 100,000 installations, exposing a wide user base to potential breaches.
The flaw was recently patched, but threat actors have already begun exploiting the vulnerability to extract configuration information, API keys, secrets, and OAuth tokens. This unauthorized access could be used in further attacks or to compromise associated services integrated with the plugin.
Why it matters
This vulnerability poses a significant risk to the confidentiality of credentials and sensitive data within websites using the Gravity SMTP plugin. Since API keys and OAuth tokens often enable access to third-party services, their leakage could facilitate broader attacks or data breaches.
Given the plugin's substantial user base, the impact scope is considerable, and exploitation could lead to compromised email delivery systems or unauthorized access to external integrations, undermining trust and security for affected sites.
What security teams should do
Administrators should verify that the latest security update for the Gravity SMTP plugin has been applied on all affected WordPress installations. Immediate patching of the CVE-2026-4020 vulnerability is crucial to prevent further unauthorized data exposure.
Security teams are also advised to review exposed API keys and OAuth tokens for signs of misuse and consider rotating them to mitigate potential compromise. Monitoring logs for irregular access patterns to the plugin's API endpoints may help detect ongoing exploitation attempts.
Key technical details
CVE-2026-4020 is classified with a CVSS score of 5.3, indicating medium severity. The vulnerability enables unauthenticated actors to perform information disclosure by exploiting inadequate access controls in the plugin.
Through this flaw, attackers can access sensitive plugin configuration details, including API keys, secrets, and OAuth tokens, which are typically stored for authenticating with external services. The flaw affects roughly 100,000 WordPress installations using the affected version of Gravity SMTP prior to the patch.
Affected organizations/products
Approximately 100,000 WordPress sites using the Gravity SMTP plugin are affected by this information disclosure vulnerability. The impact principally concerns those who have not yet applied the recent security update addressing CVE-2026-4020.
Source attribution
https://thehackernews.com/2026/06/hackers-exploit-gravity-smtp-wordpress.html