Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Gravity SMTP

Gravity SMTP Vendor Cyber Rating & Cyber Score

gravitysmtp.com

Gravity SMTP is the most powerful #SMTP management solution available for #WordPress. Take control of your transactional emails with quick and easy integrations with the best transactional email services available: #Postmark, #Sendgrid, #Mailgun, #Brevo, and many more!


Gravity SMTP A.I CyberSecurity Scoring

Gravity SMTP
Company Information
Website:https://www.gravitysmtp.com
Employees number:None
Number of followers:0
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:gravitysmtp.com
Gravity SMTP Risk Score (AI oriented)
Between 750 and 799
logo
Gravity SMTPTechnology, Information and Internet
Updated:
18/06/2026
768/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Gravity SMTP Global Score (TPRM)
xxxx
logo
Gravity SMTPTechnology, Information and Internet
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Gravity SMTP
Gravity SMTPFair
Current Score
768Baa (FAIR)
01000
1 incidents
-16 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
784Before Incident
Vulnerability
18 Jun 2026Gravity SMTP
Gravity SMTP, Mailjet, Zoho, Amazon SES and Resend: Hackers Exploit WordPress SMTP Plugin With 100,000+ Installs to Steal Sensitive Data

Critical Gravity SMTP WordPress Plugin Flaw Exploited in Mass Attacks

768After Incident
CRITICAL-16
RESZOHSMTMAIGRA1781785979
Critical Gravity SMTP WordPress Plugin Flaw Exploited in Mass Attacks Threat actors are actively exploiting a critical security vulnerability in the Gravity SMTP WordPress plugin, tracked as CVE-2026-4020 (CVSS 5.3), to extract sensitive configuration data from over 100,000 websites. The flaw, affecting all versions up to and including 2.1.4, stems from an improperly secured REST API endpoint (`/wp-json/gravitysmtp/v1/tests/mock-data`) that lacks authentication checks. Unauthenticated attackers can retrieve a 365 KB JSON system report by appending the query parameter `?page=gravitysmtp-settings`, exposing details such as PHP versions, active plugins, database configurations, and API credentials for third-party email services including Amazon SES, Google, Mailjet, Zoho, and Resend. Compromised OAuth tokens and API keys enable attackers to hijack email functionality, impersonate domains, or conduct further reconnaissance-driven attacks. The vulnerability was responsibly disclosed on March 30, 2026, after the vendor released a patched version (2.1.5) on March 17, 2026. Despite its moderate CVSS score, exploitation has surged, with Wordfence blocking over 17 million attack attempts. The most intense activity occurred between June 7–11, 2026, peaking at 4 million blocked requests on June 7 alone. The attack requires only a single unauthenticated HTTP GET request, making it trivial to exploit at scale. Wordfence deployed firewall protections for premium users on May 5, 2026, and extended coverage to free users on June 4, 2026, after observing real-world exploitation exceeding initial severity assessments. Key indicators of compromise (IOCs) include the targeted endpoint (`/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings`) and multiple malicious IP addresses, such as 45.148.10.95 (linked to over 642,000 blocked attempts). Since the flaw does not modify files or inject payloads, evidence of compromise may only appear in web server access logs. Administrators are advised to update to Gravity SMTP 2.1.5 or later and rotate exposed API keys and OAuth tokens immediately. The incident highlights how low-severity vulnerabilities can escalate into high-impact threats when sensitive data is exposed on widely used platforms like WordPress.
INCIDENT DETAILS -
TYPE
Data Exposure
MOTIVATION
Data Exfiltration, Reconnaissance, Email Hijacking
IMPACT
Data Compromised: PHP versions, active plugins, database configurations, API credentials (Amazon SES, Google, Mailjet, Zoho, Resend), OAuth tokensSystems Affected: WordPress websites using Gravity SMTP plugin (versions ≤ 2.1.4)Operational Impact: Potential email service disruption, domain impersonationBrand Reputation Impact: High (due to sensitive data exposure)Identity Theft Risk: High (if PII was exposed via compromised email services)
DATA BREACH
Type Of Data Compromised: Configuration data, API credentials, OAuth tokensSensitivity Of Data: High (API keys, database configs, email service credentials)Data Exfiltration: Yes (365 KB JSON system report)File Types Exposed: JSONPersonally Identifiable Information: Potential (if email services contained PII)
MAY 2026
784Before Incident
APRIL 2026
784Before Incident
MARCH 2026
784Before Incident
FEBRUARY 2026
784Before Incident
JANUARY 2026
784Before Incident
DECEMBER 2025
784Before Incident
NOVEMBER 2025
784Before Incident
OCTOBER 2025
784Before Incident
SEPTEMBER 2025
784Before Incident
AUGUST 2025
784Before Incident
JULY 2025
784Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Gravity SMTP ?
?
What was Gravity SMTP's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Gravity SMTP's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Gravity SMTP's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Gravity SMTP's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Gravity SMTP's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Gravity SMTP's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Gravity SMTP's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Gravity SMTP's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Gravity SMTP's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Gravity SMTP's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Gravity SMTP's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Gravity SMTP's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Gravity SMTP ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Gravity SMTP's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?