Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data Vulnerable WordPress plugin iterations leak API keys, secrets, tokens, server information, and other data. The post Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data appeared first on SecurityWeek . SecurityWeek · Jun 22, 2026 CVE-2026-4020
threat-intel ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More This week’s cybersecurity news highlights a significant Fortinet vulnerability dubbed ‘FortiBleed,’ where over 80,000 FortiGate devices have been compromised by suspected Russian-speaking threat actors. Simultaneously, t… The Hacker News · Jun 22, 2026 Critical CVE-2026-24858CVE-2025-59718CVE-2025-59719RUcredential_reuseedrransomware
vulnerability Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys A vulnerability in the Gravity SMTP WordPress plugin has been exploited by attackers, allowing them to extract sensitive data such as API keys and configuration details from approximately 100,000 sites. The flaw, tracked… The Hacker News · Jun 20, 2026 Medium CVE-2026-4020USwordpressapicredentials
vulnerability Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin Hackers are actively exploiting a vulnerability in the Gravity SMTP WordPress plugin, allowing them to access sensitive information such as API keys and email service credentials. This flaw, tracked as CVE-2026-4020, has… BleepingComputer · Jun 19, 2026 Medium CVE-2026-4020CVE-2026-8713wordpressapicredentials