{"id":57436,"date":"2026-06-20T21:46:16","date_gmt":"2026-06-21T01:46:16","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=57436"},"modified":"2026-06-20T21:46:16","modified_gmt":"2026-06-21T01:46:16","slug":"gravity-smtp-vulnerability-api-key-exposure","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/gravity-smtp-vulnerability-api-key-exposure\/","title":{"rendered":"Hackers Exploit Gravity SMTP Bug to Expose API Keys"},"content":{"rendered":"<p>Threat actors are actively exploiting a recently patched information disclosure vulnerability in the Gravity SMTP WordPress plugin, a tool installed on an estimated 100,000 websites, to harvest API keys and other sensitive configuration data. The flaw, identified as CVE-2026-4020 and carrying a CVSS score of 5.3, allows unauthenticated attackers to access a REST API endpoint that leaks a comprehensive system report, exposing everything from database credentials to active third-party email service tokens. This incident underscores how even medium-severity vulnerabilities can serve as powerful initial access vectors when the exposed data includes live credentials for critical services.<\/p>\n<h2>What Is the Gravity SMTP CVE-2026-4020 Vulnerability?<\/h2>\n<p>At its core, the vulnerability resides in a REST API endpoint registered at <code>\/wp-json\/gravitysmtp\/v1\/tests\/mock-data<\/code>codecodecodecode. The plugin\u2019s permission callback for this endpoint was coded to unconditionally return true, meaning any unauthenticated visitor to a WordPress site could access it. When the specific query parameter <code>?page=gravitysmtp-settings<\/code>codecodecodecode is appended to the request, the plugin\u2019s <code>register_connector_data()<\/code>codecodecodecode method populates internal connector data, causing the endpoint to return approximately 365 KB of JSON output containing the full System Report.<\/p>\n<h3>What Data Does This Vulnerability Expose?<\/h3>\n<p>The information returned to an unauthenticated attacker is extensive and highly damaging. It includes not only software stack configuration but also live authentication secrets. The exposed data covers:<\/p>\n<ul>\n<li>PHP version and loaded extensions<\/li>\n<li>Web server version and document root path<\/li>\n<li>Database server type and version<\/li>\n<li>WordPress version and all active plugins with their versions<\/li>\n<li>Active theme details<\/li>\n<li>WordPress configuration details and database table names<\/li>\n<li>API keys and tokens configured in the plugin, including those for Amazon SES, Google, Mailjet, Resend, and Zoho<\/li>\n<\/ul>\n<p>Because the exploit requires no authentication, any site running a vulnerable version of Gravity SMTP (prior to version 2.1.5) was effectively broadcasting its internal configuration and credentials to anyone who made the right HTTP request.<\/p>\n<h2>How Attackers Are Exploiting the Gravity SMTP Bug<\/h2>\n<p>Security researchers from <a href=\"https:\/\/www.wordfence.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Wordfence<\/a> have observed active exploit attempts since the beginning of <a href=\"https:\/\/overcentral.com\/en\/chaos-piece-may-2026-codes\/\" title=\"Chaos Piece Drops May 2026 Codes with Revamp &amp; 2x Gems\" data-iacss-internal=\"1\">May 2026<\/a>, with activity spiking dramatically around <a href=\"https:\/\/overcentral.com\/en\/nintendo-switch-2-star-fox-june-games\/\" title=\"Nintendo Switch 2 gets Star Fox and more major games in June\" data-iacss-internal=\"1\">June<\/a> 6 and reaching over 4 million blocked requests in a single day. The attackers are sending unauthenticated HTTP GET requests to the vulnerable REST API endpoint with the <code>?page=gravitysmtp-settings<\/code>codecodecodecode parameter. This triggers the server to return the verbose system report without any login requirement.<\/p>\n<p>The exploit attempts have been traced to a set of IP addresses, including: 45.148.10.95, 193.32.162.60, 176.65.148.139, 173.199.90.188, 45.148.10.120, 185.8.107.155, 185.8.106.37, 185.8.106.92, 185.8.106.145, and 176.65.148.30.<\/p>\n<h2>Why This Information Disclosure Matters<\/h2>\n<p>While the CVSS score classifies this as a medium-severity issue, the practical impact can be severe. The exposure of live third-party API credentials means an attacker could abuse the site\u2019s connected email services to send malicious emails on behalf of the organization, potentially leading to phishing attacks against the site\u2019s users, partners, or customers. Furthermore, the detailed system report\u2014including database table names, plugin versions, and the entire software stack\u2014significantly lowers the effort required to plan follow-on attacks. An attacker armed with this information can identify other vulnerabilities in the site\u2019s specific software versions and execute targeted exploits with a much higher success rate.<\/p>\n<p>As one security analysis noted, the impact ultimately depends on what specific data is exposed for each individual site. In cases where API keys for services like Amazon SES or Google are leaked, the potential for credential abuse is immediate and actionable for the attacker.<\/p>\n<h2>Patch Status and Update Guidance<\/h2>\n<p>A fix for CVE-2026-4020 has been released in Gravity SMTP version 2.1.5. Site owners who have configured third-party email integrations within the plugin should assume compromise if they were running a vulnerable version. The first priority is to update the plugin to the latest version immediately.<\/p>\n<h2>What Affected Users Should Do Now<\/h2>\n<p>If your site uses Gravity SMTP, take the following steps without delay. Update the plugin to version 2.1.5 or later. After updating, rotate all credentials for any third-party email services configured within the plugin, including API keys, secrets, and <a href=\"https:\/\/overcentral.com\/en\/klue-oauth-token-theft-icarus\/\" title=\"Klue confirms OAuth token theft in breach linked to Icarus group\" data-iacss-internal=\"1\">OAuth<\/a> tokens. This ensures that even if credentials were exfiltrated, they are no longer valid. It is also strongly advised to review server log files for any suspicious requests originating from the IP addresses listed above, specifically targeting the <code>\/wp-json\/gravitysmtp\/v1\/tests\/mock-data<\/code>codecodecodecode endpoint. For comprehensive digital security, consider implementing a multi-layered endpoint protection solution that includes web application firewall rules capable of blocking unauthenticated access to sensitive REST API endpoints. This layered approach helps mitigate the risk of similar vulnerabilities in other plugins appearing before patches are applied.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat actors are actively exploiting a recently patched information disclosure vulnerability in the Gravity SMTP WordPress plugin, a tool installed on an estimated 100,000 websites, to harvest API keys and other sensitive configuration data. The flaw, identified as CVE-2026-4020 and carrying a CVSS score of 5.3, allows unauthenticated attackers to access a REST API endpoint [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":84565,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/57436.png","fifu_image_alt":"Hackers Exploit Gravity SMTP Bug to Expose API Keys","footnotes":""},"categories":[349],"tags":[],"class_list":["post-57436","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/57436.png","fifu_image_alt":"Hackers Exploit Gravity SMTP Bug to Expose API Keys","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/57436","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=57436"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/57436\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/84565"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=57436"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=57436"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=57436"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}