Gravity SMTP WordPress Plugin: 17M Attacks, API Keys Leaking (CVE-2026-4020)
The Gravity SMTP WordPress plugin (≤2.1.4) has been hit with 17 million+ attack attempts — including 4 million in a single day. An unauthenticated info…
Security research, penetration testing, CVE analysis, PCI-DSS compliance, and defensive programming techniques for web applications.
69 ARTICLES
The Gravity SMTP WordPress plugin (≤2.1.4) has been hit with 17 million+ attack attempts — including 4 million in a single day. An unauthenticated info…
A vulnerability in the Gravity SMTP WordPress plugin is being mass-exploited, with Wordfence blocking over 17 million attempts since May 2026. The flaw lets…
F5 released emergency patches for two CVSS 9.2 critical RCE flaws in NGINX — a use-after-free in the HTTP/3 QUIC module (CVE-2026-42530) and a heap buffer…
A novel denial-of-service exploit discovered by OpenAI Codex lets a single attacker exhaust tens of gigabytes of server memory in under 20 seconds by chaining…
A critical unauthenticated privilege escalation flaw in the Kirki Customizer Framework WordPress plugin allows attackers to take over any user account —…
A critical arbitrary file deletion flaw in the Avada Builder plugin lets attackers delete wp-config.php, triggering WordPress install mode and enabling them to…
Billing software handles sensitive financial data a prime target for attackers. From SQL injection prevention to PCI-DSS compliance and token-based…
Multiple WordPress security vulnerabilities were identified in versions up to 6.3.1, including shortcode abuse, stored XSS in Footnotes and Navigation Links,…
Before you can secure a web application, you have to think like an attacker. This beginner's framework for web application penetration testing covers…