PT-2026-31907 · WordPress · Gravity Smtp

Published

2026-04-10

·

Updated

2026-04-20

·

CVE-2026-4162

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Gravity SMTP plugin for WordPress versions up to and including 2.1.4
Description The Gravity SMTP plugin for WordPress does not properly verify user authorization, allowing authenticated attackers with subscriber-level access or higher to uninstall, deactivate the plugin, and delete plugin options. This issue is also exploitable through Cross-Site Request Forgery.
Recommendations Update to a version later than 2.1.4.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4162

Affected Products

Gravity Smtp