Gravity SMTP WordPress plugin <= 2.1.4 contains a sensitive information exposure caused by an unrestricted REST API endpoint at /wp-json/gravitysmtp/v1/tests/mock-data, letting unauthenticated attackers retrieve detailed system configuration data, exploit requires no authentication.
id: CVE-2026-4020
info:
name: Gravity SMTP WordPress Plugin - Sensitive Information Exposure
au
...