Hackers Take Advantage of Gravity SMTP Plugin Vulnerability

A security issue in the Gravity SMTP WordPress plugin is being exploited by cybercriminals to access sensitive information.

3 min readSecurity

Cybercriminals are currently taking advantage of a recently addressed security vulnerability in the Gravity SMTP plugin, which is utilized by approximately 100,000 WordPress websites. This flaw, designated as CVE-2026-4020 and rated with a CVSS score of 5.3, is classified as a medium-severity issue that permits unauthorized attackers to gain access to confidential information. The data at risk includes critical configuration details, API keys, OAuth tokens, and other sensitive secrets. Website administrators are urged to ensure that their plugins are updated to the latest version to mitigate the risk of exposure. The potential for data breaches underscores the importance of maintaining robust security practices within the WordPress ecosystem.

Security