FeedHackers Exploit Gravity SMTP WordPress Plugin Bug to Expose ...
The Hacker News

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

📅 20 June 2026 at 09:56 UTC📰 The Hacker NewsView original source ↗
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000 sites. The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data, such as configuration data, API keys, secrets, and OAuth tokens

Read the full article

This is a curated summary. The complete article is available at The Hacker News.

Read on The Hacker News
← Back to feed