Vulnerability intelligence
CVE-2026-4020 — WordPress Vulnerability
CVE-2026-4020 in Gravity SMTP exposes a REST endpoint that dumps 365KB of live credentials — Amazon SES, Google, Mailjet, Zoho OAuth tokens. Patched in March. Mass exploitation started in June. 17M+ attempts blocked.
WordPress
2026
What WebPulse reported · 1 analysis
Related vulnerabilities