Back to Intelligence

CVE-2026-4020: Gravity SMTP WordPress Plugin API Key Exposure — Detection and Remediation

SA
Security Arsenal Team
June 20, 2026
1 min read

Introduction

Security Arsenal is tracking active exploitation attempts against a recently patched vulnerability in the Gravity SMTP WordPress plugin. Tracked as CVE-2026-4020

managed-socmdrsecurity-monitoringthreat-detectionsiemwordpresscve-2026-4020gravity-smtp

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.