oM noM Security Feeds cve
vulnerability context

CVE-2026-4020

CVSS 7.5 HIGHEPSS 98%CWE-200

The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor to access it. When the ?page=gravitysmtp-settings query parameter is appended, the plugin's register_connector_data() method populates internal connector data, causing the endpoint to return approximately 365 KB of JSON containing the full System Report. This makes it possible for...

Published 2026-03-31 · last modified 2026-06-17

details

CISA KEV status
Not in catalog
CVSS v3
7.5 / HIGH
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
98% percentile (score 0.3970)
CWE
CWE-200

source mentions 2

source consensus

  • Bluesky
  • The Hacker News
Want the 3-bullet summary of CVE-2026-4020, plus webhook alerts when KEV is updated? Pro is $10/mo.