The Gravity SMTP plugin for WordPress, in versions up to and including 2.1.4, is vulnerable to sensitive information exposure. This high-severity flaw (CVSS 7.5) allows unauthenticated attackers to access a REST API endpoint that, when a specific query parameter is used, returns a detailed system report. This includes critical system configuration data such as PHP and web server versions, database details, WordPress configuration, active plugins, and potentially API keys. There is currently no evidence of active exploitation or public exploit code, though the vulnerability has received some community discussion across various platforms.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| RocketGenius | Gravity SMTP | >= 0, <= 2.1.4CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.