<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Plugin-Vulnerability on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/plugin-vulnerability/</link><description>Recent content in Plugin-Vulnerability on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Fri, 20 Jun 2025 09:56:04 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/plugin-vulnerability/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-4020: Gravity SMTP Plugin API Key Leak</title><link>https://zxcloudsecurity.co.uk/posts/gravity-smtp-wordpress-plugin-cve-2026-4020-api-key-disclosure/</link><pubDate>Sat, 20 Jun 2026 09:56:04 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/gravity-smtp-wordpress-plugin-cve-2026-4020-api-key-disclosure/</guid><description>Hackers are actively exploiting CVE-2026-4020 in the Gravity SMTP WordPress plugin to steal API keys and OAuth tokens from 100,000+ sites. Patch now.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/hackers-exploit-gravity-smtp-wordpress.html">The Hacker News</a></p>
<hr>
<p>A medium-severity vulnerability in the Gravity SMTP WordPress plugin (CVE-2026-4020) is being actively exploited by attackers before many site owners have applied the patch. The flaw allows unauthenticated attackers to extract sensitive configuration data, API keys, OAuth tokens, and secrets without any login credentials. With roughly 100,000 installations affected, the potential for credential theft and downstream service compromise is significant.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> If Gravity SMTP is deployed across any WordPress instances in your environment — including headless or API-driven setups — verify the plugin is patched immediately and rotate all exposed credentials, API keys, and OAuth tokens as a precaution, since active exploitation means some keys may already be compromised.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/hackers-exploit-gravity-smtp-wordpress.html">Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys</a></p>
]]></content:encoded></item></channel></rss>