HackMyIP
← Back to News
2026-06-19 BleepingComputer

Hackers Exploit Gravity SMTP Flaw Exposing API Keys on 100K WordPress Sites

VulnerabilityThreat Intel

Threat actors are actively exploiting an unauthenticated information disclosure vulnerability in the Gravity SMTP WordPress plugin, which is installed on over 100,000 websites. Tracked as CVE-2026-4020 and rated medium severity, the flaw affects all versions up to and including 2.1.4 and was patched in version 2.1.5, released on March 17. Despite the fix being available for months, the WordPress security company Defiant reports that its Wordfence firewall has blocked more than 17 million exploitation attempts against protected customers, with a sharp spike on June 7 when 4 million requests were logged in a single day.

The vulnerability stems from a REST API endpoint in Gravity SMTP whose permission_callback always returns true, allowing unauthenticated GET requests to retrieve a comprehensive JSON System Report generated by the plugin. The exposed data includes API keys, secrets, and OAuth tokens for configured email integrations, plus credentials for third-party services such as Amazon SES, Google, Mailjet, Resend, and Zoho. The report also leaks WordPress configuration details (installed plugins, themes, and software versions), server and PHP environment data, and database configuration information including server version and table names. Website administrators concerned about credential exposure can use an email breach checker to verify whether their associated accounts have appeared in known leaks. Given that the leaked data includes live third-party API credentials, attackers can impersonate the victim organization in outbound communications, abuse connected email services, and leverage the detailed system report to plan targeted follow-on attacks with significantly reduced reconnaissance effort.

Wordfence researchers have published the most prolific source IP addresses driving exploit requests, recommending that administrators add them to their blocklists immediately. A key indicator of compromise is requests to /wp-json/gravitysmtp/v1/tests/mock-data found in web server access logs, particularly those including the ?page=gravitysmtp-settings query parameter. Administrators who have not yet updated should prioritize upgrading to Gravity SMTP 2.1.5 or later and rotate any API keys or email service credentials that were configured through the plugin. Running a full privacy checkup across associated accounts is also advisable to identify residual exposure. In a related advisory issued the same week, Defiant also disclosed CVE-2026-8713, a critical unauthenticated arbitrary file-deletion flaw in the Avada Builder plugin used on roughly one million sites, which allows path-traversal-based deletion of files such as wp-config.php, potentially reverting affected installations to their initial setup state.

Source: BleepingComputer →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →