Multiple outlets report that threat actors are actively exploiting an information disclosure vulnerability in the Gravity SMTP WordPress plugin. The flaw is described as unauthenticated, meaning an attacker can send a single HTTP request without logging in to retrieve sensitive information. Security researchers and vendors indicate the affected plugin is installed on roughly 100,000 WordPress sites, increasing the potential impact.
The exposed data is reported to include API keys, secrets, OAuth tokens, and detailed system or server configuration information. One outlet notes that the vulnerability has a published identifier, CVE-2026-4020, and characterizes it as a medium-severity issue with a CVSS score of 5.3.
Wordfence, a WordPress security firm, is cited as having blocked a very large number of exploit attempts since the activity began, suggesting ongoing scanning and exploitation attempts against vulnerable sites. The reporting across sources aligns that the core issue is the leakage of sensitive credentials and configuration data rather than direct code execution.