Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
High

Unauthenticated Sensitive Information Exposure in Gravity SMTP for WordPress

IdentifiersCVE-2026-4020CWE-200· Exposure of Sensitive Information…

CVE-2026-4020 is a sensitive information exposure vulnerability in the Gravity SMTP plugin for WordPress affecting all versions up to and including 2.1.4. The issue is caused by a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data whose permission_callback unconditionally returns true, making the endpoint accessible without authentication. When the request includes the query parameter page=gravitysmtp-settings, the plugin's register_connector_data() method populates internal connector data and the endpoint returns an approximately 365 KB JSON System Report. The exposed report can include PHP version, loaded extensions, web server version, document root path, database server type and version, WordPress version, WordPress configuration details, database table names, active plugins and their versions, the active theme, and API keys, secrets, and OAuth tokens configured for Gravity SMTP email integrations.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows any unauthenticated remote attacker to retrieve detailed reconnaissance data and potentially live secrets from affected sites. Exposed information may include API keys, OAuth tokens, and mail service credentials for integrations such as Amazon SES, Google, Mailjet, Resend, and Zoho. This can enable attackers to abuse the victim's email infrastructure, including sending email as the affected site, and to use the disclosed environment and software-stack details to identify and execute follow-on attacks against the WordPress instance or associated infrastructure.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, restrict or block unauthenticated access to the vulnerable REST API path /wp-json/gravitysmtp/v1/tests/mock-data at the web server, reverse proxy, or WAF layer. Monitor access logs for GET requests to that endpoint, particularly those including page=gravitysmtp-settings, and block abusive source infrastructure as appropriate. Treat any Gravity SMTP-managed mail integration credentials on vulnerable installations as potentially compromised until they are rotated.

Remediation

Patch, then assume compromise.

Upgrade Gravity SMTP to version 2.1.5 or later, which contains the fix for CVE-2026-4020. After patching, review web server access logs for requests to /wp-json/gravitysmtp/v1/tests/mock-data, especially requests containing page=gravitysmtp-settings, to determine whether exploitation may have occurred. Because the vulnerability may have exposed third-party integration secrets, rotate all API keys, OAuth tokens, and related credentials configured in Gravity SMTP, and reauthorize affected mail-service integrations as needed.
PUBLIC EXPLOITS

Exploits

No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.

VALID 0 / 1 TOTALView more in app

All candidate exploits were filtered out by Mallory's validation.

ACTIVITY FEED

Recent activity

79 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

xakepNews
Jun 23, 2026
Уязвимость в WordPress-плагине Gravity SMTP эксплуатируют хакеры - Хакер

Unauthenticated information disclosure vulnerability in the WordPress Gravity SMTP plugin that exposes API keys, OAuth tokens, mail service credentials, and detailed server configuration data via a REST API endpoint.

Read more
scworldNews
Jun 22, 2026
WordPress plugin Gravity SMTP exploited for sensitive information disclosure | brief | SC Media

An unauthenticated information disclosure vulnerability in the WordPress Gravity SMTP plugin caused by an exposed REST API endpoint that allows attackers to retrieve sensitive system reports containing API keys, OAuth tokens, credentials, WordPress configuration, server information, and database configurations.

Read more
security weekNews
Jun 22, 2026
Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data - SecurityWeek

A sensitive information exposure vulnerability in the Gravity SMTP WordPress plugin that allows unauthenticated attackers to access an exposed REST API endpoint and retrieve internal connector data, including system details, configuration information, and API keys/tokens.

Read more
the hacker newsNews
Jun 20, 2026
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

An information disclosure vulnerability in the Gravity SMTP WordPress plugin that allows unauthenticated access to sensitive system report data, including configuration details, API keys, secrets, and OAuth tokens, via an exposed REST API endpoint.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware1

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity70

Community discussion across Reddit, Mastodon, and other social sources.