API Keys Exposed as Hackers Exploit Gravity SMTP WordPress Plugin Bug

API Keys Exposed as Hackers Exploit Gravity SMTP WordPress Plugin Bug

A vulnerability in the Gravity SMTP WordPress plugin is being exploited to steal API keys. Site owners should update immediately and rotate credentials.

Security researchers are warning that hackers are actively exploiting a vulnerability in the Gravity SMTP plugin for WordPress. This flaw allows attackers to gain unauthorized access to API keys, which are credentials used by the plugin to communicate with email servers. The attacks are a serious threat to website owners who use this popular plugin.

Gravity SMTP is a WordPress plugin that handles the delivery of outgoing emails from a website. In technical terms, SMTP stands for Simple Mail Transfer Protocol, which is the standard method for sending emails over the internet. The plugin stores API keys, which act like secret passwords, inside the WordPress database. These keys are necessary for the plugin to authenticate with an email service and allow the site to send emails. However, the plugin contains a bug that can be exploited by hackers to read these stored keys.

When an attacker obtains an API key, they can essentially impersonate the website's email service. They might use the key to send spam or phishing emails from your domain, which can harm your reputation and lead to blacklisting. If you use a paid email service, the attacker could also rack up substantial costs. In some cases, the API keys may grant access to other data, such as contact lists or email history. This is why the exposure of API keys is considered a critical security event.

The exploit itself is likely a remote code execution or a similar vulnerability that allows the attacker to access the plugin's configuration. While the source does not provide a specific CVE identifier, the fact that the exploitation is active means that sites with outdated versions of Gravity SMTP are vulnerable. Attackers often scan the web for such vulnerable plugins, so it is crucial to patch quickly.

To protect your site, start by updating the Gravity SMTP plugin to the latest version. If you are not sure whether you have an update, check your WordPress admin panel under Plugins. Updates typically include security fixes, so this is the first line of defense. Next, rotate your API keys. This involves creating new keys in your email service's dashboard and replacing the old ones in the Gravity SMTP settings. Since the old keys may already be compromised, they should be considered invalid.

Additionally, review your sending logs and email activity. Many email providers offer detailed logs of sent messages. Look for any emails that you or your team did not send. If you find such suspicious activity, it is a sign that a key was stolen. Also, consider implementing a web application firewall (WAF) to block malicious traffic. While a WAF is a technical solution, many hosting providers offer it as part of their services.

For business owners and IT teams who manage multiple WordPress sites, staying on top of plugin updates can be a challenge. This is where managed hosting services come in. AEU Hosting provides managed WordPress hosting that is secured end to end, meaning they handle updates and security monitoring for you, reducing the risk of leaving a known vulnerability unpatched. Having a professional team manage your WordPress environment can significantly lower the chance of an attack succeeding.

How to Protect Yourself

  1. Update the Gravity SMTP plugin to the latest version as soon as possible.
  2. Rotate (change) the API keys stored in your Gravity SMTP settings by generating new ones in your email service.
  3. Check your WordPress admin for any unfamiliar changes, such as new user accounts or modified plugins.
  4. Look at your email sending logs for any messages you did not send.
  5. Enable two-factor authentication on your WordPress admin account for extra protection.

Related AEU services

  • AEU Panel Managed hosting control panel
  • AEU-I IT and security consulting