CVE-2026-4020: Gravity SMTP WordPress Plugin - Sensitive Information Exposure

HoneyLabs honeypots recorded 41 probes matching CVE-2026-4020 from 8 distinct source IP addresses in the last 7 days. Severity is rated HIGH.

Request paths that identify it

  • /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
  • /wp-json/gravitysmtp/v1/tests/mock-data

Addresses probing it

Source IPProbesNetworkCountry
195.128.248.3318Virtual Systems LLCUkraine
45.148.10.1236Techoff Srv LimitedThe Netherlands
103.153.183.696SnTHostingsUnited States
103.168.67.1593DIGI VPSUnited States
195.178.110.1053Techoff Srv LimitedBulgaria
195.178.110.1023Techoff Srv LimitedBulgaria
185.177.72.1001Bucklog SARLFrance
185.177.72.381Bucklog SARLFrance

Networks it comes from

ASNOrganisationProbesSource IPs
AS6698Virtual Systems LLC181
AS48090Techoff Srv Limited123
AS140947SnTHostings61
AS142430DIGI VPS31
AS211590Bucklog SARL22

Captured requests

  • /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-connections
  • /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
  • /wp-json/gravitysmtp/v1/tests/mock-data

HTTP client fingerprints (JA4H)

  • ge11nn0400_88d30a62b7ad
  • ge11nn05en_504771be86ae
  • ge11nn14en_068ebe3632ec
  • ge11nn0400_cf1edba2959c

CVE report

CVE report

Open a specific CVE from the CVE tracker.