Mass Exploitation of Gravity SMTP Plugin Vulnerability CVE-2026-4020

Mass Exploitation of Gravity SMTP Plugin Vulnerability CVE-2026-4020

First seen 17 Jun 2026, 09:43 UTC News.YcombinatorCybersecuritynewsGbhackersBleepingcomputerThehackernews+9 89% similarity 70.5

Article Content

Browse articles
ThreatCluster

CVE-2026-4020 is an information disclosure vulnerability in the Gravity SMTP WordPress plugin, published on March 31, 2026. The flaw allows unauthenticated visitors to access sensitive system reports, including SMTP credentials and API keys, via a REST API endpoint. Active exploitation began on May 27, 2026, with CrowdSec logging 412 distinct IPs targeting the vulnerability. A significant portion of the traffic, approximately 87%, originates from a Google Cloud fleet, indicating a coordinated operation rather than random probing. Attackers are using a rotating set of user-agents to disguise their activities, complicating detection efforts. As of June 1, 2026, exploitation has shifted into Background Noise, suggesting it has become a routine target for attackers. The vulnerability poses a serious risk to WordPress sites utilizing the Gravity SMTP plugin, as it exposes critical configuration data.

Key Points: • CVE-2026-4020 allows unauthorized access to sensitive data in Gravity SMTP plugin. • Exploitation began on May 27, 2026, with 412 distinct IPs observed targeting the vulnerability. • 87% of the attack traffic comes from a coordinated Google Cloud operation using rotating user-agents.

ThreatCluster AI How this analysis works

Timeline

2026-03-31
CVE-2026-4020 published
Information disclosure vulnerability in Gravity SMTP plugin disclosed, allowing unauthorized access to sensitive data.
www.crowdsec.net
2026-05-22
CrowdSec releases detection coverage
Detection coverage for CVE-2026-4020 was released by CrowdSec to help identify exploitation attempts.
www.crowdsec.net
2026-05-27
Active exploitation begins
CrowdSec logs the first observed exploitation of CVE-2026-4020, marking the start of active attacks.
www.crowdsec.net
2026-06-01
Exploitation shifts to Background Noise
CrowdSec classifies ongoing exploitation of CVE-2026-4020 as Background Noise, indicating routine automated attacks.
www.crowdsec.net
2026-06-17
Mass exploitation analysis published
Analysis reveals that 87% of attack traffic is from a Google Cloud fleet using rotating user-agents.
News.Ycombinator

Community

Browse all →

Tracked Entities in This Story