Security
Gravity SMTP WordPress plugin flaw exploited in attacks
Attackers are exploiting an unauthenticated information disclosure flaw (CVE-2026-4020) in the Gravity SMTP WordPress plugin, allowing access to API keys, email credentials, and server details. Over 17 million exploit attempts have been blocked since early June 2026.