www.crowdsec.net
Mass Exploitation of Gravity SMTP Plugin Vulnerability CVE-2026-4020
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
CVE-2026-4020 is an information disclosure vulnerability in the Gravity SMTP WordPress plugin, published on March 31, 2026. The flaw allows unauthenticated visitors to access sensitive system reports, including SMTP credentials and API keys, via a REST API endpoint. Active exploitation began on May 27, 2026, with CrowdSec logging 412 distinct IPs targeting the vulnerability. A significant portion of the traffic, approximately 87%, originates from a Google Cloud fleet, indicating a coordinated operation rather than random probing. Attackers are using a rotating set of user-agents to disguise their activities, complicating detection efforts. As of June 1, 2026, exploitation has shifted into Background Noise, suggesting it has become a routine target for attackers. The vulnerability poses a serious risk to WordPress sites utilizing the Gravity SMTP plugin, as it exposes critical configuration data.
Key Points: • CVE-2026-4020 allows unauthorized access to sensitive data in Gravity SMTP plugin. • Exploitation began on May 27, 2026, with 412 distinct IPs observed targeting the vulnerability. • 87% of the attack traffic comes from a coordinated Google Cloud operation using rotating user-agents.