#gravitysmtp
13 GET 404 /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings

13 times someone tried to access this yesterday. no other similar dirbuster-looking logs. just this very specific one, a whole 13 times lol
May 22, 2026 at 3:32 AM
Attackers are exploiting CVE-2026-4020 in Gravity SMTP before 2.1.5 to pull system reports from WordPress sites, exposing server details, config data, API keys, tokens, and email credentials. #GravitySMTP #CVE2026-4020 #WordPress
Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
Defiant warns that attackers are exploiting CVE-2026-4020 in the Gravity SMTP WordPress plugin to access full system reports from vulnerable sites. The exposed data can include server details, WordPress configuration, and sensitive API keys and tokens, so admins should update to Gravity SMTP 2.1.5 and rotate any exposed credentials. #GravitySMTP #CVE-2026-4020...
www.hendryadrian.com
June 22, 2026 at 1:00 PM
Critical Gravity SMTP plugin flaw exploited; update to version 2.1.5 now. #WordPress #GravitySMTP #CyberSecurity #PluginVulnerability #DataBreach #UpdateNow thedailytechfeed.com/hackers-expl...
June 18, 2026 at 9:47 AM
Are you using the GravitySMTP add-on? There is an option to force or overwrite the From name. It would also override the notification settings you set.
November 20, 2024 at 10:49 PM
📰 Peretas Eksploitasi Celah Keamanan Kebocoran Informasi pada Plugin WordPress Gravity SMTP

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/06/21/peretas-eksploitasi-celah-api-gravity-smtp-wordpress/

#ava
da#avadaBuilderh#celahKeamanan2#cve4020 #cve-2#cve8713 #explo#exploiti#gravitySmtp
June 21, 2026 at 12:09 PM
A critical info disclosure bug in Gravity SMTP allowed hackers to harvest API keys from 100,000 WordPress sites. This wasn't just a bug; it was a mass credential harvesting operation. Find out if you're affected and what to do…

https://www.tpp.blog/1hu5rdj

#cybersecurity #gravitysmtp #wordpress
June 21, 2026 at 7:15 AM
Police and international partners disrupted an Evil Corp malware network, Operation Endgame removed SocGholish servers and cleaned 14,971 WordPress sites, and The Gentlemen ransomware used GentleKiller to target 400 security processes. #Russia
Cybersecurity News | Daily Recap [20 Jun 2026]
Daily Recap, Police and international partners disrupted a malware network tied to Russia’s Evil Corp, while Operation Endgame took down SocGholish servers and cleaned 14,971 compromised WordPress sites. Security teams also warned that The Gentlemen ransomware uses the GentleKiller EDR-killer framework to target 400 security processes before encryption. #EvilCorp #OperationEndgame #SocGholish #WordPress #TheGentlemen #GentleKiller #Texas #FortiBleed #Fortinet #Klue #Icarus #GravitySMTP #usbliter8 #SecureROM #AppleA12 #AppleA13 #AutoJack #Beats #Continuum
www.hendryadrian.com
June 21, 2026 at 11:45 PM
testing was executed by an Inbound Exploit Probe utilizing GravitySMTP test vectors targeting multiple domain extensions, which was instantly counter-balanced by parallel cloud resource observations from a Secondary Independent Network Gateway and an Amazon Web
August 26, 2026 at 10:42 AM
Five Eyes says frontier AI hacking models could arrive within months, while INTERPOL reports rising phishing and AI scams in Asia-Pacific. North Korean links, WordPress plugin attacks, and D-Link botnet activity continue. #NorthKorea #INTERPOL
Cybersecurity News | Daily Recap [22 Jun 2026]
Daily Recap, Five Eyes warns that advanced AI hacking models could reach the cyber scene within months, while INTERPOL reports rising phishing and AI-powered scams across Asia-Pacific. In addition, North Korean activity is linked to the Mastra NPM supply-chain attack, attackers are targeting the Gravity SMTP WordPress plugin, and the AryStinger botnet continues infecting D-Link routers. #FiveEyes #INTERPOL #Mastra #NPM #NorthKorean #GravitySMTP #WordPress #AryStinger #DBlink #DLink #TexasParksAndWildlife #Ukraine #EU
www.hendryadrian.com
June 23, 2026 at 2:00 AM
Hackers are exploiting CVE-2026-4020 in Gravity SMTP, a WordPress plugin on 100,000 sites, to expose API keys, secrets, and OAuth tokens via a REST endpoint. #GravitySMTP #CVE20264020 #Wordfence
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Threat actors are actively exploiting CVE-2026-4020 in Gravity SMTP, a WordPress plugin used on about 100,000 sites, to steal sensitive configuration data, API keys, secrets, and OAuth tokens. Wordfence has blocked over 17 million attempts, and site owners should update to version 2.1.5 and rotate exposed credentials immediately. #GravitySMTP #CVE-2026-4020 #Wordfence...
www.hendryadrian.com
June 20, 2026 at 7:45 PM
Hackers are exploiting CVE-2026-4020 in Gravity SMTP, affecting 100,000+ WordPress sites and exposing API keys, OAuth tokens, and email credentials via a REST endpoint. #GravitySMTP #CVE20264020 #WordPress
Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
Threat actors are actively exploiting CVE-2026-4020 in the Gravity SMTP WordPress plugin, which affects more than 100,000 sites and can expose sensitive API keys, OAuth tokens, and email service credentials. Wordfence has already blocked over 17 million attempts, while a separate critical flaw, CVE-2026-8713 in Avada Builder, can let attackers delete arbitrary files and potentially take over sites. #GravitySMTP #CVE20264020 #Wordfence #AvadaBuilder #CVE20268713
www.hendryadrian.com
June 19, 2026 at 11:45 PM
Wordfence: CVEs críticos WordPress 15-21 jun 2026

¿Qué CVEs afectaron WordPress la semana del 15-21 de junio 2026? El reporte vulnerabilidades WordPress Wordfence confirma 2 críticos con exploit activo ...

#wordfence #cve20264020 #cve20261830 #vulnerabilidadeswordpress #gravitysmtp
Wordfence: vulnerabilidades críticas WordPress mayo 2026 - Seguridad en Wordpress
Wordfence Intelligence publicó su reporte semanal con casos críticos como CVE-2026-40776 en Eventin y el ataque de supply chain que comprometió 30+ plugins durante ocho meses.
seguridadenwordpress.com
June 26, 2026 at 2:04 AM
Gravity SMTP: exploit expone claves API en WordPress

Actualizá Gravity SMTP: la vulnerabilidad de WordPress expone claves API sin login. Rotá credenciales antes que alguien comprometa tu servidor de correo.

#gravitysmtp #vulnerabilidadwordpress #smtpexploit #apikeysexpuestas #seguridadwordpress
Gravity SMTP: exploit expone claves API en WordPress - Seguridad en Wordpress
Un fallo de autorización en Gravity SMTP expone claves de API y credenciales SMTP sin autenticación. Así funciona el exploit y cómo proteger tu sitio.
seguridadenwordpress.com
June 22, 2026 at 3:09 AM
Gravity SMTP: la falla que expone tus claves sin login

412 IPs atacan la vulnerabilidad Gravity SMTP que expone claves SMTP sin autenticación. Actualizá a 2.1.5 y rotá credenciales antes de que sea tarde.

#gravitysmtp #cve20264020 #pluginswordpress #seguridadsmtp #wordfence
Gravity SMTP: la falla que expone tus claves sin login - Seguridad en Wordpress
CVE-2026-4020 expone credenciales SMTP de tu WordPress sin autenticación. Actualizá a 2.1.5 y rotá claves de inmediato.
seguridadenwordpress.com
June 17, 2026 at 6:50 PM
CVE-2026-4020 - Gravity SMTP
CVE ID : CVE-2026-4020

Published : 31 Mar 2026, 2:15 a.m. | 49 minutes ago

Description : The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST ...
CVE-2026-4020 - Gravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API
The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor to access it. When the ?page=gravitysmtp-settings query parameter …
cvefeed.io
March 31, 2026 at 4:00 AM
Hackers exploit Gravity SMTP plugin flaw, exposing API keys. Update now. #WordPress #Security #GravitySMTP #CVE20264020 #PluginVulnerability #CyberSecurity thedailytechfeed.com/hackers-expl...
June 20, 2026 at 10:36 AM
CVE-2026-4162 #WordPress plugin #vulnerability gravitysmtp (CVSS Score 7.1) #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge
CVE-2026-4162 – gravitysmtp Proof of Concept - Atomic Edge
CVE-2026-4162 vulnerability in gravitysmtp WordPress plugin. Proof of concept, ModSecurity rule, and patched version analysis by Atomic Edge.
atomicedge.io
April 19, 2026 at 10:33 PM