Attackers Actively Exploiting Gravity SMTP Flaw to Leak API Keys from WordPress Sites

Attackers Actively Exploiting Gravity SMTP Flaw to Leak API Keys from WordPress Sites

A critical vulnerability in the Gravity SMTP plugin for WordPress is being actively exploited, allowing attackers to steal API keys and compromise email services. Site owners should update immediately and review their co…

A severe security flaw in the popular Gravity SMTP WordPress plugin is being actively exploited by hackers to steal API keys, putting website email functionality and data at risk. The plugin, which enables WordPress sites to send email through third-party SMTP services like SendGrid, Mailgun, or Amazon SES, contains a bug that can expose the API credentials stored in its settings. Security researchers have observed live attacks targeting unpatched installations, making this an urgent threat for site administrators.

Gravity SMTP simplifies transactional email delivery from WordPress, but the plugin's vulnerability allows unauthorized users to extract sensitive API keys. These keys grant access to the underlying email service accounts, which attackers can then abuse to send spam, launch phishing campaigns, or even exfiltrate stored email logs and contact lists. For businesses relying on their email infrastructure for customer communication, a breach could lead to reputational damage, blacklisting, and financial loss. The exact technical nature of the bug has not been fully disclosed to prevent further exploitation, but it is believed to stem from insufficient access controls or improper data handling within the plugin.

Site owners using Gravity SMTP should immediately update to the latest patched version of the plugin and rotate all API keys associated with their SMTP accounts. It is also critical to inspect recent email-sending activity for any anomalies, such as unexpected spikes in volume or messages sent to unknown recipients. Additionally, checking for unauthorized admin user accounts or modified WordPress files can help identify whether a compromise has already occurred. The active exploitation of this flaw underscores the importance of rapid patching and regular security reviews for WordPress plugins, which are frequent targets for attackers.

For website owners seeking a more resilient security posture, managed WordPress hosting services like AEU Hosting provide continuous monitoring and automated plugin updates to protect against vulnerabilities like this Gravity SMTP flaw. By handling core and plugin patches proactively, such platforms reduce the window of exposure and help ensure that email credentials and other sensitive configurations remain secure from exploitation.

Related AEU services

  • AEU Panel Managed hosting control panel
  • AEU-I IT and security consulting