Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that’s installed on about 100,000 sites.

The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data, such as configuration data, API keys, secrets, and OAuth tokens

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and

Petition against Meta’s employee training data collection for ML models

Petition against Meta’s employee training data collection for ML models Source: Hacker News

Typing Speed Test, but for Developers

Typing Speed Test, but for Developers Source: Hacker News