Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025
Security Vulnerabilities

Gravity SMTP WordPress plugin flaw exploited in attacks

Hackers are actively targeting a medium-severity vulnerability in the Gravity SMTP plugin, exposing sensitive data on 100,000 WordPress sites.

Gravity SMTP WordPress plugin flaw exploited in attacks
AI25.Studio Studio · Pexels

WordPress site administrators are being urged to update the Gravity SMTP plugin after security researchers confirmed active exploitation of a vulnerability that exposes sensitive system and email service credentials. The flaw, tracked as CVE-2026-4020, affects all versions of the plugin up to and including 2.1.4, which is installed on approximately 100,000 sites. A patch was released on March 17, 2026, but many sites remain unprotected as attack volumes surge.

The vulnerability stems from an improperly secured REST API endpoint in Gravity SMTP. The endpoint’s permission_callback function returns true by default, allowing unauthenticated GET requests to retrieve a detailed "System Report" in JSON format. This report includes API keys, OAuth tokens, and credentials for third-party email services such as Amazon SES, Google, Mailjet, Resend, and Zoho. It also reveals WordPress configuration details, server environment information, and database structure, providing attackers with a roadmap for further compromise.

What happened

Security firm Defiant, which operates the Wordfence firewall, reported blocking over 17 million exploit attempts targeting CVE-2026-4020. Exploitation activity spiked on June 7, 2026, with 4 million requests blocked in a single day, and remained elevated for several days afterward. The most active source IP addresses have been identified and shared for blocking. A key indicator of compromise is the presence of requests to /wp-json/gravitysmtp/v1/tests/mock-data in web server access logs, particularly those containing the query parameter ?page=gravitysmtp-settings.

While the vulnerability is rated as medium severity, its impact is significant. Exposed email service credentials can be used to impersonate the victim, send phishing emails, or conduct further attacks. The detailed system report also lowers the barrier for attackers to identify and exploit additional vulnerabilities in the site’s software stack. Defiant researchers warned that the combination of live API credentials and comprehensive system data "significantly lowers the effort required to plan further attacks against the site."

Why it matters

The Gravity SMTP plugin is widely used to manage email delivery for WordPress sites, making it a high-value target for attackers. The exposed data can lead to email account takeovers, which are often used for business email compromise (BEC) scams, phishing campaigns, or spreading malware. Additionally, the server and database details included in the system report can be leveraged to craft targeted attacks, such as SQL injection or remote code execution, against vulnerable sites.

WordPress site owners are advised to update to Gravity SMTP version 2.1.5 or later immediately. Administrators should also review their email service configurations for unauthorized changes and rotate any exposed credentials. Monitoring web server logs for suspicious requests to the vulnerable endpoint can help identify compromised sites.

For professionals

For professionals: Site administrators should audit their WordPress plugins for outdated versions and prioritize updates for those handling sensitive data or email services. Implementing a web application firewall (WAF) can help block exploit attempts while patches are applied. Additionally, consider isolating email service credentials from WordPress configurations where possible to limit exposure in the event of a similar vulnerability.

In a separate advisory, Defiant also warned about a critical vulnerability in the Avada Builder plugin (CVE-2026-8713), which allows unauthenticated arbitrary file deletion on sites using the plugin. While no active exploitation has been observed, the flaw could lead to full site takeover if critical files like wp-config.php are deleted. The issue was patched in version 3.15.4 of Avada Builder.

Discussion · coming soon

Be the first to join the thread when community discussion launches.