The Hacker News
"Hackers exploit Gravity SMTP Wordpress Plugin bug to expose API keys." Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents. Accessed on 21 June 2026, 1512 UTC. Content and Source: "The Hacker News." URL--https://thehackernews.com/ Please check URL or scroll down to read your selections. Thanks for joining us today. Russ Roberts (https://www.hawaiicybersecurityjournal.net). Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys Jun 20, 2026 Vulnerability / Web Security Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000 sites. The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data, such as configuration data, API keys, secrets, and OAuth tokens configured for the plugin's email int...