Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Verilumia

The Daily Verified Briefing

Markets

Gravity SMTP Plugin Flaw Exploited to Steal Credentials

Published 21 June 2026

A significant vulnerability in a widely used WordPress plugin is being actively exploited by attackers to steal sensitive credentials and system information from websites. The flaw, tracked as CVE-2026-4020, affects the Gravity SMTP plugin, which is installed on more than 100,000 WordPress sites.

© 2026 Verilumia Ltd. All rights reserved.

Verified, fact-checked news you can trust.

0:00 / 0:00