Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP a WordPress plugin thats installed on about 100000 sites The vulnerability tracked as CVE20264020 CVSS score 53 is a mediumseverity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data such as configuration data API keys secrets and OAuth tokens