Attackers Actively Exploiting Sensitive Information Exposure Vulnerability in Gravity SMTP Plugin

On March 30th, 2026, we publicly disclosed a Sensitive Information Exposure vulnerability in Gravity SMTP, a WordPress plugin with an estimated 100,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to retrieve detailed system configuration data and, critically, any API keys, secrets, and OAuth tokens configured for the plugin’s email integrations.

The post Attackers Actively Exploiting Sensitive Information Exposure Vulnerability in Gravity SMTP Plugin appeared first on Wordfence.

This article has been indexed from Blog – Wordfence

Read the original article: