www.crowdsec.net Mass Exploitation of Gravity SMTP Plugin Vulnerability CVE-2026-4020
Article Content
- •CVE-2026-4020 allows unauthorized access to sensitive data in Gravity SMTP plugin.
- •Exploitation began on May 27, 2026, with 412 distinct IPs observed targeting the vulnerability.
- •87% of the attack traffic comes from a coordinated Google Cloud operation using rotating user-agents.
CVE-2026-4020 is an information disclosure vulnerability in the Gravity SMTP WordPress plugin, published on March 31, 2026. The flaw allows unauthenticated visitors to access sensitive system reports, including SMTP credentials and API keys, via a REST API endpoint. Active exploitation began on May 27, 2026, with CrowdSec logging 412 distinct IPs targeting the vulnerability. A significant portion of the traffic, approximately 87%, originates from a Google Cloud fleet, indicating a coordinated operation rather than random probing. Attackers are using a rotating set of user-agents to disguise their activities, complicating detection efforts. As of June 1, 2026, exploitation has shifted into Background Noise, suggesting it has become a routine target for attackers. The vulnerability poses a serious risk to WordPress sites utilizing the Gravity SMTP plugin, as it exposes critical configuration data.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (15)
Following this threat?
Track CVE-2026-4020 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Langflow AI Platform Targeted by RCE Exploitation In September 2026, the Langflow AI application-building platform faced significant exploitation attempts targeting CVE-2026-0768, an unauthenticated remote code execution vulnerability. F5 Labs reported 405 requests from 55 distinct source IPs, indicating a coordinated effort to exploit this flaw. The vulnerability…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…