Executive brief
Gravity SMTP is a WordPress plugin used to manage and improve the reliability of outgoing emails. A security flaw allows logged-in users with low-level permissions (such as subscribers) to deactivate the plugin, uninstall it, or delete its configuration settings. This could disrupt website email communications, such as contact form notifications or password resets, and potentially lead to a loss of administrative settings.
Technical details
The Gravity SMTP plugin for WordPress suffers from a missing authorization vulnerability (CWE-862) in versions up to 2.1.4. The software fails to perform adequate permission checks on administrative actions, allowing any authenticated user with subscriber-level privileges or higher to trigger plugin deactivation, uninstallation, and the deletion of plugin options. Additionally, the lack of proper nonce validation makes these actions exploitable via Cross-Site Request Forgery (CSRF) if an administrator interacts with a malicious link. The issue is resolved in version 2.1.5.
Affected products
- Gravity Forms Gravity SMTP up to, and including, 2.1.4
Timeline
- 2026-03-25: patched: Version 2.1.5 released with security enhancements.
- 2026-04-10: disclosed: Vulnerability details published by Wordfence and NVD.