Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A high-severity unauthenticated vulnerability in the Gravity SMTP WordPress plugin (CVE-2026-4020) exposes live email service credentials, including API keys and OAuth tokens for Amazon SES, Google, Mailjet, Resend, and Zoho, to any unauthenticated attacker who queries a single REST API endpoint. Approximately 100,000 active installations are affected, and exploitation has exceeded 17 million blocked attempts, with a single-day spike of 4 million requests on June 7, indicating active, widespread scanning. Organizations still running version 2.1.4 or earlier face immediate risk of email infrastructure takeover, bulk spam abuse, sensitive data exfiltration, and downstream account compromise across connected services.

Author

Tech Jacks Solutions