
Critical Gravity SMTP WordPress Plugin Flaw Exposes API Keys to Attackers
A security bug in the Gravity SMTP WordPress plugin is being actively exploited to steal SMTP service API keys, potentially giving hackers control over a site’s outgoing emails.
A critical vulnerability in the Gravity SMTP WordPress plugin is currently under active exploitation, allowing attackers to extract API keys from affected sites. The flaw, which security researchers have confirmed is being weaponized in the wild, puts any WordPress installation using the plugin’s SMTP relay feature at risk. Once an API key is exposed, malicious actors can take over a website’s email sending capability, leading to phishing campaigns, spam distribution, and further compromise of the connected email service accounts.
Website owners who rely on the Gravity SMTP plugin to route transactional emails through third-party services like SendGrid, Mailgun, or Amazon SES are especially vulnerable. The exposed credentials could allow attackers to read email logs, reset passwords, or impersonate the website’s domain in social engineering attacks. Because SMTP credentials handle outbound email, a breach can damage sender reputation and cause legitimate system messages—such as password reset and order confirmation emails—to be blocked or flagged as spam.
The developers of Gravity SMTP have released a patched version that fixes the underlying exposure. All users are urged to update immediately to the latest plugin release. In parallel, website administrators should rotate any API keys that may have been compromised, as simply patching the plugin does not invalidate stolen credentials. Security teams should also review mail server logs for any suspicious sending activity or unauthorized access patterns.
This incident highlights the importance of keeping WordPress plugins up to date and limiting the permissions granted to external service credentials. While many site owners handle updates manually, the volume of plugin vulnerabilities can be overwhelming. AEU Hosting’s managed WordPress platform helps site owners stay protected by automatically applying security patches and monitoring for known plugin vulnerabilities, reducing the window of exposure when flaws like this come to light.
How to Protect Yourself
- If you use the Gravity SMTP plugin on your WordPress site, update it to the latest version right away by logging into your dashboard, going to Plugins, and clicking “Update Now” next to the plugin.
- After updating, log in to your SMTP provider (e.g., SendGrid, Mailgun) and generate a new API key, then replace the old one in the plugin settings to stop misuse of the exposed key.
- Check your email service’s sending history for any emails you do not recognize, and report suspicious activity to the provider.
- Use two-factor authentication on your email sending service account to add an extra lock, so even if a key leaks, a stolen password alone cannot give full access.
- If you manage multiple WordPress sites, consider a hosting service that automatically handles plugin updates and vulnerability scans for you.