Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

CVE-2026-4020 is an actively exploited unauthenticated information disclosure vulnerability in the Gravity SMTP WordPress plugin, allowing attackers to retrieve API keys and credentials stored by the plugin without authentication. Any organization running this plugin on a public-facing WordPress site should patch immediately and rotate all credentials stored or processed by the plugin.

Author

Tech Jacks Solutions