Attackers are actively exploiting a vulnerability in the Gravity SMTP WordPress plugin that can expose sensitive system information, including API keys, OAuth tokens, plugin inventories, and server configuration details without authentication. While the flaw does not directly enable remote code execution, it highlights a persistent security challenge in the WordPress ecosystem: information disclosure vulnerabilities are often underestimated until attackers use the exposed data for reconnaissance, credential theft, and follow-on attacks.
Gidi Cohen, CEO & Co-founder, Bonfy.AI had this comment
“The active exploitation of the Gravity SMTP vulnerability (CVE‑2026‑4020) to steal API keys, secrets, and full system details from WordPress sites shows how even minor plugins now sit on the front line of enterprise data exposure. An unauthenticated REST endpoint returning configuration data, plugin inventories, and third‑party email credentials gives attackers both the ability to impersonate a brand and high‑quality reconnaissance for chaining additional exploits.
Updating to version 2.1.5 and rotating exposed keys is critical, but this incident reflects a broader problem: a growing web of plugins, SaaS connectors, and AI‑enabled services moving sensitive content with limited content‑level governance. Modern data security strategies increasingly need to treat every outbound channel as a high‑risk path requiring consistent, contextual, content‑aware controls and to provide unified visibility into how unstructured data moves across websites, SaaS apps, collaboration tools, and AI systems.”
Vusal Shahbazzade, Lead Edge Deployment Engineer, Polygraf AI follows with this:
“What’s interesting about CVE-2026-4020 is not a severity score (5.3 is medium), but it gives to an attacker. It includes a REST endpoint that that authenticates nobody and returns the site’s full system report (PHP version, server paths, active plugins, database details, configured API keys). It’s not the medium level problem in practice, because that data opens many other doors – everything shown in clean JSON, no skill required to read it. On top of it 17 million blocked attempts are people building a map.
This bug lives in a shared configuration library bundled into the plugin, an endpoint that registered itself as public without anyone explicitly deciding it should be. It’s a convenience feature in a dependency exposed one by default, and it inherited the trust of the plugin it shipped inside. Teams would beed to audit every endpoint a dependency registers, rather than assuming they’re safe, otherwise low-CVSS bugs will keep doing high-CVSS damage.”
If I were you, either update this plugin to version 2.1.5 or discontinue its use. Either way, you’ll be doing yourself a favour.
Posted in Commentary with tags CData on June 23, 2026 by itnerd
CData Software today launched three products for developers building AI applications on enterprise data: Connect AI Developer Edition (free), the CData Connect AI Python SDK (open source), and CData CLI.
The releases give developers direct, governed access to enterprise systems, Salesforce, Snowflake, NetSuite, Microsoft 365, Workday, and hundreds of others, through the interfaces they already use: SQL, Python, the command line, and MCP.
Most enterprise AI projects stall at the data layer, not because the models are wrong, but because getting governed, reliable access to production systems requires IT involvement at every step. Connect AI is what IT deploys so developers don’t have to ask for permission each time. Business teams get AI workflows. Developers get a stable data interface. IT gets visibility and control over every query.
Connect AI Developer Edition
Connect AI exposes enterprise APIs as a consistent, queryable data layer with standardized schema, read/write support, and automatic handling of authentication, rate limits, versioning, and pagination. Developers write queries. The platform handles the rest.
The free Developer Edition includes the full enterprise feature set: MCP server support, per-user authentication passthrough, query logging with user-level attribution, and a management MCP server. It works out of the box with any MCP-capable coding assistant, client, or framework, including Claude Code, Codex, Cursor, and LangChain, among others.
Connect AI also ships with Toolkits, which let teams package governed data access into a single MCP Server URL scoped to specific use cases, so agents get exactly what they need and nothing more.
Connect AI Python SDK
The Python SDK provides DB-API-compliant access to Connect AI, so developers can pull governed enterprise data into existing Python workflows without changing how they write code. It works with pandas, SQLAlchemy, cursor-based queries, and any other DB-API-compatible tool.
The SDK is open source and available now.
CData CLI
CData CLI is a command-line interface for CData’s JDBC, ODBC, Python, and ADO.NET connectors, designed to speed up development and testing for analytics pipelines, BI integrations, and ETL workflows. It’s built for how developers work today: CLI-native tooling that coding assistants like Claude Code and Cursor can use directly to scaffold connectivity without digging through documentation. The initial release supports JDBC, with support for ADO.NET, Python, and ODBC coming in future releases.
Probook, the AI Operating System for home service businesses, today announced $40 million in funding. The investment comprises a $34 million Series A led by Andreessen Horowitz (a16z) and a $6 million Seed round led by Sequoia Capital. Sequoia also participated in the Series A.
Home service operators spent the last three years buying AI. A voice agent. A chat widget. A follow-up tool. Each one owned a slice of the customer, and none of them talked to each other. Every vendor built for the top of the funnel, where leads come in — and ignored dispatch, the brain of every home service business, where customer experience is made or broken. Operators ended up with a stack of point solutions and a piecemeal customer experience.
Probook built dispatch first. Intake, data cleaning, customer messaging, and outbound came next, only possible because everything shares one context layer. Every customer stays on one text thread, with one number, from the first touch through the front door. Every inbound lead is answered with perfect information. Every booking is cleaned before assignment. Humans manage exceptions. Techs sell more. Shops run more jobs. Operators add points to their EBITDA and, for the first time, run a connected customer experience.
George Eliadis spent a summer inside TR Miller, a $40M HVAC, plumbing, and electrical shop in Illinois that became Probook’s first customer. There, he saw the same problems at scale.
Probook deploys with customers in person, configures the platform alongside their front-line teams, and stays on the hook for the outcomes it sells.
Probook serves customers across hundreds of locations nationwide, from independently owned shops to private equity-backed platforms. Notable customers include TurnPoint Services, Master Trades Group, Del-Air, Peterman Brothers, and Sila Services.
Summers Plumbing, Heating & Cooling, with 14 locations and 260 technicians on the platform, booked 2,542 jobs in its first month on Probook with zero human intervention.
Del-Air, an 8-location operation in Florida, runs Probook across the stack. “We chose Probook
over other AI vendors because they know dispatch. They’re also part of our front-line CSR,” noted Rick Rogers, CEO.
Konstantine Buhler, Partner at Sequoia Capital, added: “Most founders building for the trades have never worked in them. George has. Pair that with the team’s outlier technical depth, and you see why we backed Probook at Seed and why we’re doubling down now.”
Probook will use the capital to scale its go-to-market team against surging demand, and grow engineering and customer success to deliver on it.
Posted in Commentary with tags Dragos on June 23, 2026 by itnerd
Dragos today announced the release of EmberAI, an OT-native AI built on the Dragos Intelligence Fabric, the world’s largest OT cybersecurity data set. EmberAI gives every analyst immediate access to Dragos OT-specific intelligence gained from over a decade of OT actions, activity and knowledge.
Putting historical and real-time intel in the hands of every security analyst, EmberAI enables teams to gain detailed visibility into assets, vulnerabilities, and network activity across their OT environment. They can prioritize threats by operational impact and act on findings specific to their environment. EmberAI empowers every analyst, regardless of experience, to move from alert to informed action faster, and make defensible decisions grounded in real adversary data.
Threat activity against critical infrastructure is accelerating. Concurrently, the OT cybersecurity skills gap to address these complex tactics and techniques is widening. Existing tools prioritize visibility over understanding, and general-purpose AI lacks the operational context to distinguish a critical exposure from background noise or to prioritize threats by their actual impact on operations. In OT, any delayed or incorrect decision can have direct consequences to operational safety, resilience, and control.
Organizations responsible for securing extended operational technology (xOT) environments, including power grids, manufacturing plants, water systems, pipelines, and data center environments, need AI that is built on the right intelligence and grounded in operational reality. EmberAI empowers analysts across the full range of experience—from IT practitioners and plant engineers operating in OT environments to seasoned OT professionals—to gain the situational visibility and awareness, intelligence and actionality of an OT expert to prioritize what matters operationally, and act effectively on findings that threaten safe operations.
The Dragos Intelligence Fabric is built on over five petabytes of daily OT telemetry, 10-plus years of adversary tracking across named OT threat groups, proprietary OT vulnerability research as a CVE Numbering Authority, asset and protocol research spanning more than 600 OT protocols, and frontline incident response experience from critical infrastructure environments. The Dragos Intelligence Fabric continuously learns as new intelligence surfaces, field insights accumulate, and threat groups adopt new behaviors.
This foundation enables EmberAI to operate on a principle that distinguishes it from generic AI: OT specific intelligence applied in context. EmberAI is central to Dragos’s xOT security strategy—the company’s architecture for securing Extended Operational Technology, the full environment of systems influencing critical operational processes. As xOT integrations expand the Intelligence Fabric with new data sources, EmberAI’s intelligence and capabilities will grow with it.
How It Works
Intelligence-Driven Query Engine: Analysts ask questions in plain language and receive precise, OT-contextual answers grounded in the Dragos Intelligence Fabric. This eliminates the need to manually pivot across disconnected tools or correlate data from multiple sources.
Contextual Correlation Across the Environment: EmberAI connects assets, vulnerabilities, threat intelligence, and network activity into a unified, real-time understanding. Decisions are based on full operational context, not isolated or irrelevant technical signals.
Adversary-Informed Guidance: Detections and alerts are mapped to known OT threat groups, observed attack patterns, and real behaviors drawn from the Dragos Intelligence Fabric. Analysts understand not just what is happening, but what it means for their environment and what to do from a prioritization approach.
Workflow Acceleration and Automation Support: From alert triage to incident summaries and reporting, EmberAI reduces hours of friction laden and often error prone manual work. Analysts spend less time gathering data and more time making informed decisions.
Expert-Built OT Skills: Dragos analysts are building and validating a rich library of guided, repeatable workflows. Encoding the same expertise they apply during proactive services, investigations, and incident response, this library will be available soon.
Continuous Learning Through the Intelligence Fabric: As new intelligence and field insights surface, Dragos Intelligence Fabric evolves—and EmberAI becomes more efficient and effective. Design Principles
The analyst remains in control at every step. Every recommendation EmberAI surfaces is transparent and auditable, enabling defensible workflows. Customer data never leaves the customer’s environment. EmberAI operates inside the Dragos Platform deployment the organization already controls. These design choices reflect a foundational “human in the loop” principle about OT: the person responsible for protecting an environment must own the final decision.EmberAI is generally available today inside the Dragos Platform.
On June 23, the Women’s Engineering Society’s International Women in Engineering Day (INWED) will mark its 13th year, once again shining a spotlight on the achievements and contributions of women engineers worldwide. The 2026 theme, #EngineeringIntelligence, highlights the innovation, expertise, and impact women bring to the engineering profession.
Estelle Azemard, CEO, Leaseweb Canada, and Chrissay Brinkmann, Sales Support & Technical Delivery, Leaseweb USA had this to say:
“It’s interesting. If you go back a few decades, engineering was often viewed as a fairly straightforward discipline. You were building a bridge. Designing a system. Solving a technical problem specifically. As a society, today, engineering sits at the center of almost every major conversation. AI. Sustainability. Healthcare. Transportation. Energy. Digital infrastructure. Engineers are helping shape what the future looks like, in many important ways.
That’s just one of the reasons International Women in Engineering Day is important. The challenges we’re facing are not getting less complicated, they’re growing. And when problems get more challenging, different perspectives become incredibly valuable. The industry talks a lot about talent shortages. And, rightly so. We do indeed need more engineers. We need more innovators. We need more people willing to tackle difficult problems, in new ways. Creating opportunities for more women to enter and thrive in engineering isn’t simply good for representation. It’s good for engineering. Because the future is going to belong to the organizations that can bring together and deploy the best ideas, regardless of where they come from.”
Chrissay Brinkmann, Sales Support & Technical Delivery, Leaseweb USA
“The fact that the work is never really finished, is one thing I’ve always found fascinating about engineering. Every time you solve one problem… technology advances, expectations change, and suddenly there’s a new problem waiting for you. You’re constantly learning, adapting, and figuring things out – that’s part of what makes the field so rewarding.
Cybernews researchers uncovered an exposed server belonging to a threat actor that contained documentation of attacks against accommodation-sector companies, source code, hacking tool configurations, and stolen booking data.
Key findings:
Researchers found at least 50 penetration test reports targeting accommodation companies.
Researchers say the hacker bypassed LLM guardrails by disguising malicious intent as penetration testing.
The attacker used HexStrike AI, an open-source tool that integrates large language models (LLMs), together with Anthropic’s Claude.
The exposed server contained stolen booking-related data, including guests’ personally identifiable information (PII) such as names, emails and phone numbers.
Researchers observed 2.1 million unique email addresses in exported files, which most likely correlated to the number of exposed individuals.
The attacker took the server out of public view during the investigation, but the Cybernews team managed to identify at least 4 affected companies, including a Canadian one.
The leaked data included records from IGMS, a Canadian company that specializes in Property Management Software (PMS) development. Extracted data included host phone numbers, check-in and check-out dates, host emails, property address, and, in some cases, WiFi passwords. Researchers observed 1,400 records from IGMS.
The researchers warn that stolen reservation data can be used in highly convincing phishing campaigns, especially when attackers know guests’ names, travel dates, and reservation details.
Findings from the dark web reveal that discussions surrounding deepfakes as a service have exploded in 2026, already surpassing 2025’s totals and potentially paving the way for a new wave of business email compromise attacks
The latest findings from NordStellar, a threat exposure management platform, reveal that dark web discussions surrounding cybercrime as a service are trending upward in 2026. Deepfakes as a service is proving especially popular, with posts surging 39% in the first five months of 2026 — already surpassing the total volume recorded in 2025 and potentially giving cybercriminals new tools for “fake boss” scams.
According to data analyzed by NordStellar, 9,234 dark web posts discussed cybercrime as a service (CaaS) in 2025. Between January and May 2026 alone, that number has already reached 6,866 — representing 74% of last year’s total.
The analysis reveals that discussions about deepfakes as a service (DFaaS) are growing the fastest. In just the first five months of 2026, there were 924 posts — marking a 39% increase compared to the 663 posts recorded for all of 2025.
“The rapid growth in popularity of deepfakes as a service is likely accelerated by advancements in generative AI, which help cybercriminals in two ways — by speeding up the creation of deepfakes and making them hyper-realistic,” says Vakaris Noreika, cybersecurity expert at NordStellar. “Ultimately, this service lowers the barrier to entry for deepfake technology, enabling threat actors to deploy highly deceptive attacks at a larger scale, regardless of their personal technical skill set.”
Deepfakes for business email compromise attacks
Noreika highlights that the growing popularity of DFaaS is a key concern for businesses. Cybercriminals can leverage deepfakes not only to target individuals with sophisticated social engineering but also to amplify business email compromise (BEC), otherwise commonly known as “fake boss” scams. In these attacks, bad actors impersonate vendors, colleagues, or executives to manipulate employees.
The FBIreports that business email compromise was the second costliest cybercrime of 2025, with company losses exceeding $3 billion. This marks an 11% increase over $2.7 billion reported in 2024.
The real-life case covered by the World Economic Forum involving engineering firm Arup highlights the stakes: An employee was tricked into transferring $25 million after attending a video call where all other participants were AI-generated deepfakes.
“Deepfakes can be used to elevate business email compromise attacks to make them even harder to spot — instead of receiving fake payment instructions in an email, employees can now be targeted via highly realistic video and voice calls impersonating partners or managers asking them to transfer funds,” says Noreika. “As AI tools grow more sophisticated, deepfakes are evolving rapidly. It is now easier than ever to create convincing video or audio that lacks the usual telltale signs of AI generation, making it extremely challenging for users to spot the deception — especially when a sense of urgency is involved.”
He explains that cybercriminals usually deploy these attacks to obtain fake payments or confidential documents or to infiltrate the company’s network to launch a larger-scale attack. Advanced BEC attacks usually involve gathering extensive intel on the target to ensure that the attack itself contains convincing details, is context-appropriate, and is delivered at the right time — for example, when the recipient is already waiting for an incoming invoice.
Deepfake defense strategies in the era of AI
Noreika suggests that a deepfake-resistant cybersecurity strategy should focus on two main areas — prevention and employee education. While companies can’t control whether cybercriminals target them, robust security measures can make advanced BEC attacks much harder to execute.
“The more details and access attackers obtain, the easier it is for them to craft highly realistic, targeted attacks,” says Noreika. “Monitoring the dark web for leaked company information is a critical step in preventing cybercriminals from finding credentials to breach accounts or data to use as intel.”
He emphasizes that educating employees on BEC attacks is vital. However, he notes that fostering a positive cybersecurity culture is equally important.
“Attackers take advantage of their targets by creating a sense of urgency,” says Noreika. “Even if employees are aware of cybercriminals’ tactics, slowing down to double-check a request that’s coming from a person of authority can be daunting to most, especially if deadlines are tight. Efficiency shouldn’t come at the expense of possibly exposing the company to a cyberattack, and employees should feel safe and empowered to raise red flags when something is off, and take some time to inspect the request before diving headlong.”
Noreika stresses that having a robust cybersecurity strategy in place will help mitigate the aftermath of a BEC attack if threat actors succeed in tricking employees and gain access to the company’s network. He notes that security measures like network segmentation and multi-factor authentication can help prevent attackers from moving laterally inside the network as well as prevent them from accessing resources.
Methodology: The NordStellar platform was used to analyze underground discussions from dark web forums and monitored Telegram channels. NordStellar tracked 6 categories covering as-a-service offerings. For each category, NordStellar retrieved monthly post counts across both forums and Telegram for every month from January 2024 through May 2026. For more information, visit NordStellar’s blog post.
Disclaimer. This analysis is based on detected activity and is for informational purposes only; it does not constitute professional advice or a guarantee of security. All third-party trademarks and references remain the property of their respective owners and are used for identification purposes only.
Finite State has announced that Chief Security Officer Sharon Hagi will present the keynote address “AI Closes the Window: Automotive Supply Chain Security in an Accelerated Threat Environment” at the Auto-ISAC (Information Sharing and Analysis Center) Europe Cybersecurity Workshop, 11:40 a.m.–12:10 p.m. Wednesday, June 24, 2026, at the Spazio Ferrari Maranello in Maranello, Italy.
The session will explore the evolving realities of securing software-defined vehicle ecosystems and scaling defensible product security workflows across modern automotive development environments.
With connected vehicle ecosystems becoming increasingly software-defined, automotive organizations face growing pressure to manage software complexity across ECUs and supply chains, reduce vulnerability noise, and continuously demonstrate security and compliance readiness across the product lifecycle.
Hagi’s keynote is designed to help European OEMs, suppliers, and mobility providers navigate evolving cybersecurity regulations, vulnerability disclosure expectations and issues, and the operational realities of securing modern vehicle platforms built on rapidly changing software.
Recognizing that fragmented tools and manual workflows cannot keep pace with the scale and complexity of firmware-heavy systems, supplier ecosystems, and continuous software delivery, the session will help equip automotive security and engineering teams to move at the speed of modern vehicle development.
Finite State Live Demonstrations
The Finite State team will run live demonstrations of artifact-backed workflows for connected vehicle security with:
Unified product intelligence – analyzing and connecting firmware, binaries, source, and supplier inputs into a complete, continuously updated system of record grounded in what actually ships across ECUs and vehicle platforms
Exploitability-based prioritization – focusing on real exposure using reachability and context, with a defensible rationale for what matters across in-vehicle systems and what does not
New CVE to impacted vehicle platforms – enabling teams to move from vulnerability disclosure to impact analysis quickly, with consistent VEX decisions and traceable outputs across ECUs, builds, and variants
Design-to-deployment traceability – connecting architecture, threats, risks, and requirements directly to deployed vehicle software, and keeping them aligned as systems evolve
Continuous compliance outputs – automatically generating SBOM, VEX, traceability, and audit-ready reports that stay current across releases and support evolving automotive cybersecurity regulations
Attendees interested in meeting with the Finite State team during the Auto-ISAC Europe Cybersecurity Workshop 2026 canbook a meeting here.
Internet-facing business telephone systems are being targeted through sustained and automated attacks designed to steal credentials and generate fraudulent international calls, CloudSEK researchers have found.
During an 18-day observation period, a controlled Session Initiation Protocol, or SIP, honeypot recorded more than 15.18 million telemetry events, representing approximately 3.79 million SIP requests from 323 source IP addresses.
The campaign included 1,869,521 authentication attempts against 29,433 telephone extensions and 89,465 attempted calls, indicating a coordinated attack pipeline moving from reconnaissance and password spraying to suspected financial fraud.
CloudSEK researchers recovered a live attacker dictionary containing 277,632 unique passwords and 1.49 million extension-password combinations. The plaintext password used could be determined in 96.09% of all credential attempts.
The findings show that attackers were not relying only on weak passwords. The dictionary also contained medium- and high-complexity credentials, suggesting the use of device defaults, previously exposed passwords and attacker-curated wordlists.
UK Numbers Dominated Suspected Toll-Fraud Activity
Of the 89,465 attempted calls, 47,273 targeted United Kingdom numbers, primarily across a limited set of rural and Northern Ireland ranges.
The activity was consistent with International Revenue Share Fraud, in which criminals attempt to use compromised or misconfigured business phone systems to call revenue-generating numbers, leaving the victim organisation responsible for the charges.
Attackers repeatedly dialled the same destinations using different international and outbound prefixes to identify a format permitted by the PBX. One UK number was attempted using more than 80 prefix variations.
Credential Replays Point to a Wider Operation
Researchers also identified 45,580 authentication attempts containing credentials or authentication realms harvested from other systems.
These included references to Asterisk, Intelbras, Grandstream and STARFACE systems, as well as external and private IP addresses associated with other PBX environments.
The findings indicate that some attackers may be maintaining a broader collection of scanned or compromised phone systems and reusing harvested authentication material across multiple targets.
Attacks Originated Primarily from Hosting Infrastructure
CloudSEK found that 99.8% of source-attributed traffic originated from datacenter or hosting ranges, while 93.5% of attacker IP addresses were already listed by third-party intelligence services as known sources of abuse.
The campaign operated continuously throughout the day, indicating unattended automation. Attackers also spoofed legitimate device identities, including FreePBX, Cisco, Polycom and Avaya, to make malicious traffic appear genuine.
The study was conducted using a controlled honeypot that recorded attack activity but did not accept credentials or complete any calls.
Posted in Commentary with tags Rogers on June 22, 2026 by itnerd
Truly from the WTF category comes this $4-$5 increase in their cellular bills from Rogers (five dollars) and Fido (four dollars). And to add insult to injury comes the fact that some people have joined as little as three months ago. Here’s what iPhone In Canada posted:
Rogers is adding a $5 monthly increase for select wireless customers, set to kick in on or after July 15, 2026. The justification mirrors what Fido told its own customers, a vague nod to network investment. The note on Rogers bills says the company continuously invests in its 5G network to deliver “Canada’s most reliable” experience, and that the monthly fee for affected plans is going up by $5 plus tax to help cover those costs.
Instead of just raising the plan price outright, Rogers is tacking the charge on as its own line item called Wireless Plan Rate Adjustment. That wording has already drawn criticism online, with some customers pointing out that breaking the fee out separately might be a way to get around price guarantees or fixed-rate promises.
What being talked about here is that the CRTC has hit the big three hard in terms of junk fees that stop people from moving carriers easier. So instead of explicitly calling out the fee increases, Rogers and Fido are instead shifting the prices around to bury them as much as possible so that they can’t be called out . Rogers for its part said this on their bill:
“We continuously invest to bring you Canada’s most reliable 5G+ network and the best mobile experience in Canada.”We continuously invest to bring you Canada’s most reliable 5G+ network and the best mobile experience in Canada. To help support these investments, the monthly fee (Monthly Charge) for your wireless price plan will increase by $5 (plus taxes), starting with your next bill, on or after July 15, 2026. This will appear as an additional line item under Monthly Charges on your monthly bill called Wireless Plan Rate Adjustment. The rest of your wireless services remain the same. If you have any questions or no longer wish to subscribe to your wireless service, please reach out to us as indicated in the Contact Us section of this bill.”
But people are not impressed. Some of which phoned me out of desperation. My advice is simple. Freedom Mobile hasn’t got the best coverage. But they have good enough coverage that for most people, their travels in the GTA are good enough. Ditto for many metropolitan areas as well. Plus they have done away with the junk fees that the CRTC is trying to ban. That on top of the fact that my last few trips overseas has seen a substantial reduction in roaming charges. While Freedom isn’t for everyone, that is a solution for Rogers (and ultimately TELUS and Bell) screwing customers over.
Active exploitation of Gravity SMTP flaw exposes hidden WordPress risk
Posted in Commentary with tags WordPress on June 23, 2026 by itnerdAttackers are actively exploiting a vulnerability in the Gravity SMTP WordPress plugin that can expose sensitive system information, including API keys, OAuth tokens, plugin inventories, and server configuration details without authentication. While the flaw does not directly enable remote code execution, it highlights a persistent security challenge in the WordPress ecosystem: information disclosure vulnerabilities are often underestimated until attackers use the exposed data for reconnaissance, credential theft, and follow-on attacks.
You can get an overview here: CVE-2026-4020: Gravity SMTP WordPress Plugin Exploited
Gidi Cohen, CEO & Co-founder, Bonfy.AI had this comment
“The active exploitation of the Gravity SMTP vulnerability (CVE‑2026‑4020) to steal API keys, secrets, and full system details from WordPress sites shows how even minor plugins now sit on the front line of enterprise data exposure. An unauthenticated REST endpoint returning configuration data, plugin inventories, and third‑party email credentials gives attackers both the ability to impersonate a brand and high‑quality reconnaissance for chaining additional exploits.
Updating to version 2.1.5 and rotating exposed keys is critical, but this incident reflects a broader problem: a growing web of plugins, SaaS connectors, and AI‑enabled services moving sensitive content with limited content‑level governance. Modern data security strategies increasingly need to treat every outbound channel as a high‑risk path requiring consistent, contextual, content‑aware controls and to provide unified visibility into how unstructured data moves across websites, SaaS apps, collaboration tools, and AI systems.”
Vusal Shahbazzade, Lead Edge Deployment Engineer, Polygraf AI follows with this:
“What’s interesting about CVE-2026-4020 is not a severity score (5.3 is medium), but it gives to an attacker. It includes a REST endpoint that that authenticates nobody and returns the site’s full system report (PHP version, server paths, active plugins, database details, configured API keys). It’s not the medium level problem in practice, because that data opens many other doors – everything shown in clean JSON, no skill required to read it. On top of it 17 million blocked attempts are people building a map.
This bug lives in a shared configuration library bundled into the plugin, an endpoint that registered itself as public without anyone explicitly deciding it should be. It’s a convenience feature in a dependency exposed one by default, and it inherited the trust of the plugin it shipped inside. Teams would beed to audit every endpoint a dependency registers, rather than assuming they’re safe, otherwise low-CVSS bugs will keep doing high-CVSS damage.”
If I were you, either update this plugin to version 2.1.5 or discontinue its use. Either way, you’ll be doing yourself a favour.
Leave a comment »