CVE-2026-4020 is an information disclosure flaw in Gravity SMTP, a WordPress email plugin from Rocketgenius that reports put on about 100,000 sites. A REST API endpoint meant for test data had no real permission check, so a single unauthenticated GET request could return the plugin's full System Report, including the API keys, OAuth tokens and SMTP passwords the site uses to send email. Version 2.1.5, released in March 2026, fixed it, and the CVE was published on 31 March 2026. Mass exploitation followed: Wordfence says it blocked more than 17 million attempts, peaking at over 4 million on a single day in June 2026, and one hosting provider found that 86 of its sites had leaked mail credentials. The identities at stake were not WordPress users but the non-human credentials that connect a website to Amazon SES, Google, Mailgun and other sending services.
Key takeaways
- Gravity SMTP versions up to and including 2.1.4 expose
/wp-json/gravitysmtp/v1/tests/mock-datato anyone. With?page=gravitysmtp-settingsadded, it returns about 365 KB of JSON, including any API keys or tokens configured in the plugin. - Rocketgenius's changelog dates the 2.1.5 release to 25 March 2026; the CVE and the GitHub advisory were published on 31 March 2026.
- Exploitation was observed in the wild. Anchor Hosting logged its first confirmed leak on 19 April, CrowdSec saw exploitation from 27 May, and Wordfence reported more than 17 million blocked attempts with a peak around 6 to 7 June 2026.
- The "100,000 sites" figure is the plugin's reported install base, not a count of sites that leaked keys. No public source gives a total number of compromised sites.
- Lesson: patching closes the hole but does not revoke what already leaked. Every API key and SMTP password stored in a vulnerable plugin needs rotating, and each one should be scoped so that a leak is limited to sending mail.
At a glance
| Affected | WordPress sites running Gravity SMTP 2.1.4 or earlier; reported install base of about 100,000 sites |
|---|---|
| Vendor | Rocketgenius |
| Disclosed | Fix in version 2.1.5 (25 March 2026 per the vendor changelog); CVE published 31 March 2026; exploitation reported in June 2026 |
| Severity | CVSS 3.1 score of 7.5 (High) in the GitHub advisory record; The Hacker News reported 5.3 and BleepingComputer described it as medium |
| Attacker | Automated mass scanning from hundreds of IP addresses; no named group |
| Entry point | Unauthenticated REST API endpoint whose permission check always allowed access |
| Identities abused | Email service API keys, OAuth tokens and SMTP credentials (Amazon SES, Google, Mailjet, Resend, Zoho, Mailgun) stored in the plugin |
| Impact | More than 17 million exploit attempts blocked by Wordfence; 86 sites at one host leaked Mailgun credentials; site environment details exposed for follow-on attacks |
| Category | NHI (API keys, OAuth tokens and service credentials), vulnerability |
What happened
Gravity SMTP lets a WordPress site send email through third-party providers instead of the web server's own mail function. To do that, the site owner stores provider credentials in the plugin: API keys, OAuth tokens or SMTP usernames and passwords. Those credentials are machine identities. They authorise a website, not a person, to send mail in the organisation's name.
According to the GitHub advisory for CVE-2026-4020, the plugin registered a REST API route at /wp-json/gravitysmtp/v1/tests/mock-data with a permission callback that "unconditionally returns true, allowing any unauthenticated visitor to access it." When the request included the query parameter ?page=gravitysmtp-settings, the endpoint returned "approximately 365 KB of JSON containing the full System Report". That report included the PHP version and extensions, web server and database details, WordPress configuration, every active plugin and its version, the active theme and "any API keys/tokens configured in the plugin". The advisory classifies the flaw as CWE-200, exposure of sensitive information to an unauthorised actor.
Rocketgenius's changelog lists version 2.1.5, dated 25 March 2026, with the single line "Added security enhancements." BleepingComputer and The Next Web give 17 March as the release date; Anchor Hosting, which cites the changelog date, says the fix shipped "six days before CVE-2026-4020 became public". The CVE and GitHub advisory were published on 31 March 2026 and apply to all versions up to and including 2.1.4.
The patch did not stop attackers from finding sites that had not updated. Anchor Hosting, a WordPress host, first heard of the problem from its email provider. Austin Ginder of Anchor Hosting wrote that "A compliance specialist at Mailgun reached out about recent activity on my account. Two of my client sending domains had been suspended." Going back through its logs, Anchor found the earliest probe on 17 April 2026 and the first confirmed credential leak on 19 April. It counted 806 distinct scanning IP addresses and 36 days of continuous scanning between 30 April and 4 June. Anchor said a single GET request to the endpoint returned the System Report "which includes the live SMTP connection settings", with a response body of about 22 to 24 KB on its sites.
CrowdSec added detection on 22 May 2026 and observed the first in-the-wild exploitation on 27 May. In a report dated 1 June it counted 412 distinct attacking IP addresses in the following days and concluded that "Attackers have added it to the checklist", treating the endpoint as routine automated reconnaissance.
The scale became public in mid-June. Wordfence, the WordPress security product from Defiant, said it had blocked more than 17 million exploit attempts. The Hacker News, reporting Wordfence's data, described "initial activity commencing at the start of May 2026" and a spike "around June 6, 2026, touching a high of over 4,000,000 requests a day later". BleepingComputer reported Wordfence's warning that "The exposure of live third-party API credentials means an attacker could abuse the site's connected email services". Both outlets listed the exposed provider credentials as Amazon SES, Google, Mailjet, Resend and Zoho, and published attacker IP addresses as indicators.
Timeline
| Date | Event |
|---|---|
| 26 February 2026 | Gravity SMTP 2.1.4, the last vulnerable version, released according to the vendor changelog. |
| 25 March 2026 | Version 2.1.5 released with "security enhancements" (BleepingComputer and The Next Web report 17 March). |
| 31 March 2026 | CVE-2026-4020 and GitHub advisory GHSA-jxfc-8wcq-xxcg published, covering versions up to 2.1.4. |
| 17 to 19 April 2026 | Anchor Hosting's earliest detected probe (17 April) and first confirmed credential leak (19 April). |
| Early May 2026 | Start of exploitation activity seen by Wordfence, according to The Hacker News. |
| 27 May 2026 | CrowdSec observes first in-the-wild exploitation. |
| 28 May 2026 | Mailgun suspends two of Anchor Hosting's client sending domains. |
| 30 May to 5 June 2026 | Anchor Hosting rotates 1,289 Mailgun keys. |
| 6 to 7 June 2026 | Exploitation spikes; Wordfence blocks more than 4 million requests on 7 June. |
| 17 to 20 June 2026 | Wordfence warns of active exploitation; coverage by Suped, BleepingComputer and The Hacker News follows. |
How it happened: the identity attack path
- Credentials stored in a plugin. Site owners put email provider API keys, OAuth tokens and SMTP passwords into Gravity SMTP so the site could send mail. Those secrets lived in the WordPress environment, readable by the plugin's code.
- A test route with no gate. The mock-data REST route used a permission callback that always returned true. Any visitor on the internet could call it without logging in.
- The system report as a secrets dump. Adding
?page=gravitysmtp-settingsmade the endpoint return the full System Report, which carried the configured keys and tokens alongside a detailed map of the site's software. - Mass scanning after the patch. Automated scanners probed WordPress sites at scale for weeks after the fix. Sites that had not updated to 2.1.5 handed over their credentials to whoever asked.
- Abuse of trusted sending identities. With a working API key or SMTP password, an attacker can send mail through a service that the victim's domain already authorises. Suped notes this can pass SPF and DKIM checks and damage the domain's sending reputation. At Anchor Hosting, abusive sending led Mailgun to suspend domains.
- Stale credentials as the weak point. Anchor found that "The only domain anyone actually sent from was a customer I no longer had", an orphaned account whose credentials were still live.
Impact
- Exposure: the plugin's reported install base is about 100,000 sites according to BleepingComputer and The Hacker News. That is the population potentially exposed before patching, not a confirmed count of leaked keys.
- Attempts: Wordfence reported more than 17 million blocked exploit attempts, with over 4 million on 7 June 2026 alone.
- Confirmed leaks at one host: Anchor Hosting found 86 sites that leaked credentials and rotated 1,289 keys. It reported "eighty-six stolen sending credentials and zero site compromises", with no new admin accounts and no logins from scanning IPs.
- Reconnaissance value: CrowdSec found 55% of observed victims were commerce environments and 39% small office or home office deployments, and characterised the leaked environment data as useful for follow-on attacks.
What this means for NHI governance
CVE-2026-4020 did not give attackers control of WordPress. It gave them something quieter and often more useful: working credentials for the services that send an organisation's email. An Amazon SES key or a Mailgun SMTP password is a non-human identity with a very specific privilege, the right to send mail as the domain. Because the domain's SPF and DKIM records already trust that service, messages sent with a stolen key can look more legitimate than ordinary spoofing.
The case shows three recurring NHI weaknesses. First, secrets were stored in application configuration where any bug in that application could read them, and one debugging route was enough. Second, patching and credential hygiene were treated as the same task. They are not: updating to 2.1.5 closed the endpoint, but every key read before the update stayed valid until someone rotated it. The Hacker News reported advice that affected owners "should assume compromise, and rotate the credentials after updating". Third, ownership. The one domain that attackers actually used at Anchor belonged to a departed customer, a credential nobody was watching and nobody had revoked.
The pattern echoes other secrets exposed by a single request, such as the MongoBleed memory leak, and hard-coded keys that turned into remote code execution in Gladinet's products. Anchor's conclusion applies to all of them: "all of us need to be ready to rotate keys at the first sign of a potential problem."
Recommendations
- Update and check logs. Move to Gravity SMTP 2.1.5 or later and search access logs for requests to
gravitysmtp/v1/tests/mock-data. Anchor Hosting says a 200 response of around 22 to 24 KB on its sites meant credentials were handed over. - Rotate every stored mail credential. Treat any API key, OAuth token or SMTP password configured in a vulnerable version as exposed, and replace it at the provider, not just in WordPress. The API Key Management Guide covers rotation and retirement.
- Scope sending keys tightly. Use provider keys restricted to sending from specific domains, with rate limits and alerts on unusual volume, so a leaked key cannot read logs, manage domains or send unlimited mail.
- Keep secrets out of plugin settings where possible. Load credentials from environment variables or a secrets manager rather than the database, and keep them out of diagnostic output. See the Secrets Management Guide.
- Revoke credentials for departed customers and projects. Maintain an owner for every API key and remove keys when the site or client they served is gone, as set out in the NHI Ownership and Accountability Guide.
- Prepare for bulk rotation. Hosts and agencies managing many sites need a tested way to rotate hundreds of keys quickly. Challenges of Rotating NHIs explains why this is hard at scale.
Frequently asked questions
What is CVE-2026-4020 in Gravity SMTP?
It is an unauthenticated information disclosure flaw in the Gravity SMTP WordPress plugin, versions 2.1.4 and earlier. A REST API endpoint for test data allowed anyone to request the plugin's System Report, which included configured email API keys and tokens along with server and WordPress details.
Was CVE-2026-4020 exploited?
Yes. Wordfence reported more than 17 million blocked exploit attempts, peaking in early June 2026, CrowdSec observed exploitation from 27 May 2026, and Anchor Hosting confirmed that 86 of its sites leaked Mailgun credentials, with one domain used to send mail.
Did 100,000 WordPress sites leak API keys?
No source shows that. About 100,000 is the plugin's reported install base. Sites were exposed only if they ran 2.1.4 or earlier and had provider credentials configured, and no public total of leaked keys exists.
Related NHI Mgmt Group resources
MongoBleed MongoDB secrets exposure · Gladinet hard-coded keys exploited · OneLogin API key vulnerability · API Key Management Guide · NHI breaches
How NHI Mgmt Group can help
API keys and SMTP credentials sitting in application settings are non-human identities, and a single exposed endpoint can hand them to anyone who asks. Our NHI Foundation Level Training Course helps teams find where these credentials live, assign owners and rotate them before a leak becomes abuse.
References
- GitHub Advisory Database: CVE-2026-4020, Gravity SMTP sensitive information exposure (GHSA-jxfc-8wcq-xxcg) (31 March 2026)
- Gravity SMTP: Gravity SMTP Changelog, version 2.1.5 (25 March 2026)
- CrowdSec: CVE-2026-4020, Gravity SMTP Information Disclosure Under Active Exploitation (1 June 2026)
- Anchor Hosting: Gravity SMTP Exploit Campaign (9 June 2026)
- Suped: Gravity SMTP flaw exposes email sending credentials during mass exploitation (18 June 2026, updated 19 August 2026)
- BleepingComputer: Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin (19 June 2026)
- The Hacker News: Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys (20 June 2026)
- The Next Web: Hackers are mass-exploiting a Gravity SMTP flaw to steal API keys from 100,000 WordPress sites (20 June 2026)