CVE-2026-4020: Gravity SMTP WordPress Plugin - Sensitive Information Exposure
HoneyLabs honeypots recorded 18 probes matching CVE-2026-4020 from 5 distinct source IP addresses in the last 7 days. Severity is rated HIGH.
Request paths that identify it
- /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
- /wp-json/gravitysmtp/v1/tests/mock-data
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 93.123.109.214 | 7 | Techoff Srv Limited | Bulgaria |
| 172.105.109.85 | 6 | Akamai Connected Cloud | Canada |
| 172.236.28.161 | 2 | Akamai Connected Cloud | United Kingdom |
| 50.116.58.253 | 2 | Akamai Connected Cloud | United States |
| 45.148.10.74 | 1 | Techoff Srv Limited | The Netherlands |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS63949 | Akamai Connected Cloud | 10 | 3 |
| AS48090 | Techoff Srv Limited | 8 | 2 |
Captured requests
- /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
CVE report
CVE report
Open a specific CVE from the CVE tracker.