Detects WordPress installs running the Gravity SMTP plugin at version 2.1.4 or earlier. The plugin registers a REST API endpoint at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true. When the ?page=gravitysmtp-settings parameter is appended, the endpoint returns ~365KB of JSON containing the full system report: PHP version, loaded extensions, web server version, document root, database info, all active plugins with versions, WordPress config, database table names, and configured SMTP API keys/tokens.
Is your app exploitable through CVE-2026-4020?
Scan your domain free