Skip to content

SECURITY: Gravity SMTP plugin CVE-2026-4020 - API keys exposed #51

Description

@muhamedfazalps

Gravity SMTP plugin has CVE-2026-4020. API keys, secrets, OAuth tokens exposed to unauthenticated visitors. 100K+ sites affected.

Fix: Update or deactivate Gravity SMTP plugin.

Source: Wordfence, The Hacker News (June 20, 2026)

Support: https://www.buymeacoffee.com/muhamedfazalps

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions