← WordPress Vulnerabilities
WordPress security by component

Gravity SMTP

Gravity SMTP is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Mar 31, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: gravitysmtp

CVE-2026-4020: Gravity SMTP: Sensitive information exposure

Gravity SMTP is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The published affected range is <= 2.1.4.

PublishedMar 31, 2026
Known safe version> 2.1.4
Safe version
Mar 31, 2026 CVE-2026-4020
Gravity SMTP: Sensitive information exposure
Gravity SMTP is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The published affected range is <= 2.1.4.
> 2.1.4
CVE7.5
NVDPending