Welsh ICP Conviction 🏴🏉[verified]@ICPLEGEND1966Active Exploitation
The Gravity SMTP WordPress plugin (CVE‑2026‑4020) is being widely exploited with over 17 million attack attempts; a patch (v2.1.5) is required, and the post emphasizes the urgency of remediation.
Teegra 🧝♀️𝕏[verified]@TeeegraActive Exploitation
Hackers are actively exploiting the CVE-2026-4020 vulnerability in the Gravity SMTP plugin to harvest sensitive configuration data from about 100,000 WordPress sites.
DFIR Radar[verified]@DFIR_RadarDisclosure
The tweet discloses that CVE-2026-4020 in Gravity SMTP allows an unauthenticated GET request to a specific API endpoint to retrieve API keys, OAuth tokens, and full system data, with a CVSS score of 5.3.
Wordfence[verified]@wordfenceActive Exploitation
The article reports that CVE-2026-4020 in Gravity SMTP is being actively exploited, with millions of attack attempts detected, and advises users to update to version 2.1.5.
Anavem.com[verified]@Anavem_Disclosure
CVE-2026-4020 allows unauthenticated attackers to retrieve confidential configuration and database information from Gravity SMTP installations, potentially affecting hundreds of thousands of WordPress sites.
Cyber Edition[verified]@CyberEditionActive Exploitation
The tweet reports that attackers are exploiting CVE-2026-4020 in Gravity SMTP on WordPress sites, exposing sensitive credentials, and urges users to update to mitigate the vulnerability.
CyberX[verified]@CyberXlx9qActive Exploitation
CVE-2026-4020 in the Gravity SMTP plugin is actively exploited, enabling attackers to harvest sensitive credentials; administrators should update to 2.1.5+ and rotate exposed keys.
Elusive[verified]@ElusivePrivacyActive Exploitation
CVE‑2026‑4020 in Gravity SMTP permits unauthenticated attackers to exfiltrate sensitive configuration data and OAuth tokens, with evidence that it is already being exploited; the vendor is urged to patch immediately.