Skip to content

[GHSA-jxfc-8wcq-xxcg] The Gravity SMTP plugin for WordPress is vulnerable to...#8099

Open
nickpelton wants to merge 1 commit into
nickpelton/advisory-improvement-8099from
nickpelton-GHSA-jxfc-8wcq-xxcg
Open

[GHSA-jxfc-8wcq-xxcg] The Gravity SMTP plugin for WordPress is vulnerable to...#8099
nickpelton wants to merge 1 commit into
nickpelton/advisory-improvement-8099from
nickpelton-GHSA-jxfc-8wcq-xxcg

Conversation

@nickpelton

Copy link
Copy Markdown

Updates

  • Affected products
  • References
  • Summary

Comments
The reference links were to wordpress trac system, this is a premium plugin that is not on the WP trac repository. Removed the links.

The vulnerability was patched in version 2.1.5 on Mar 25

Copilot AI review requested due to automatic review settings June 23, 2026 13:42
Copilot stopped work on behalf of nickpelton due to an error June 23, 2026 13:42
@github-actions github-actions Bot changed the base branch from main to nickpelton/advisory-improvement-8099 June 23, 2026 13:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the OSV advisory record for GHSA-jxfc-8wcq-xxcg / CVE-2026-4020 (Gravity SMTP WordPress plugin) to better reflect affected versions and adjust references.

Changes:

  • Added a summary field.
  • Populated affected with a version range and database_specific.last_known_affected_version_range.
  • Updated references to remove WordPress Trac links and add a CVE.org link.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

"aliases": [
"CVE-2026-4020"
],
"summary": "CVE-2026-4020",
Comment on lines +19 to +22
"package": {
"ecosystem": "Packagist",
"name": ""
},

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a private plugin. There is no public package. I was not given the choice to not choose an ecosystem. It's technically WordPress.

Comment on lines +36 to +38
"database_specific": {
"last_known_affected_version_range": "< 2.1.4"
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants