S4E just found a medium log file scanner
high·Product Based Web Vulnerabilities·Updated Apr 1, 2026

CVE-2026-4020 Scanner

CVE-2026-4020 Scanner - Information Disclosure vulnerability in Gravity SMTP WordPress Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-4020
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor to access it. When the ?page=gravitysmtp-settings query parameter is appended, the plugin's register_connector_data() method populates internal connector data, causing the endpoint to return approximately 365 KB of JSON containing the full System Report. This makes it possible for unauthenticated attackers to retrieve detailed system configuration data including PHP version, loaded extensions, web server version, document root path, database server type and version, WordPress version, all active plugins with versions, active theme, WordPress configuration details, database table names, and any API keys/tokens configured in the plugin.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Gravity SMTPby RocketGenius
0
Updated Aug 19, 2026View on NVD →
Detail

The Gravity SMTP WordPress Plugin is commonly used on WordPress websites to configure SMTP settings for email delivery, ensuring reliable email communication. It is widely utilized by website administrators and developers to enhance email delivery reliability and security. It integrates seamlessly with existing WordPress installations, allowing users to set up and manage their SMTP configurations. This plugin is essential for WordPress sites relying on transactional and notification emails, providing better deliverability compared to built-in PHP mail functions. It supports various SMTP services allowing site owners to select their preferred email delivery method. Overall, the plugin plays a crucial role in the email management infrastructure of WordPress sites.

The Information Disclosure vulnerability in the Gravity SMTP WordPress Plugin manifests through an unrestricted REST API endpoint. This unprotected endpoint allows unauthenticated attackers to retrieve sensitive information. The vulnerability can expose detailed system configuration data, potentially leading to more severe exploits. As it affects versions up to and including 2.1.4, it is imperative to address this issue to maintain system integrity. The specifics of this vulnerability underline the importance of configuring secure REST API access permissions. Consequently, developers and admins must be vigilant in applying patches promptly.

Technical details highlight a REST API endpoint, '/wp-json/gravitysmtp/v1/tests/mock-data', which lacks proper access controls. This vulnerability is exploited by sending a GET request to the endpoint, returning JSON-formatted data. The response contains confidential configuration details like 'gravitysmtp_admin_config', 'system_report_clipboard', and 'feature_flags'. A successful attack requires no authenticated session and depends solely on accessible endpoints on the victim's server. Responses with 200 status codes signify vulnerability presence, further evidenced by specific keywords within the body part of HTTP responses.

If exploited, attackers could perform reconnaissance to gather sensitive information vital for orchestrating subsequent attacks, increasing potential system security compromises. Information potentially exposed includes admin configurations, contributing to vulnerabilities like privilege escalation. Worse case scenarios involve attackers leveraging the gathered configuration details to infiltrate or disrupt other connected systems. System integrity becomes at risk through information leakage. Thus, protecting this data from falling into malicious hands ensures a holistic defense against sophisticated multiphase attacks.

REFERENCES

Solution Advice
  • Update the Gravity SMTP WordPress Plugin to a version beyond 2.1.4 immediately to mitigate known vulnerabilities.
  • Ensure all REST API endpoints are secured with appropriate access control mechanisms to prevent unauthorized data retrieval.
  • Regularly audit API access permissions and logs to detect and respond to unauthorized attempts.
  • Implement monitoring tools to track unusual activities or access patterns relating to sensitive endpoints.
  • Review other plugins and configurations for potential security weaknesses to maintain overall site integrity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.