# Gravity SMTP Plugin Flaw Exposes API Keys and Secrets on 100,000 WordPress Sites
A critical information disclosure vulnerability in the widely-deployed Gravity SMTP WordPress plugin is being actively exploited by threat actors to steal email service credentials and reconnaissance data from tens of thousands of websites. Security firm Wordfence has blocked over 17 million exploitation attempts against its protected customers, signaling a rapid and sustained attack campaign targeting the flaw.
## The Threat
CVE-2026-4020, rated as medium severity, allows unauthenticated attackers to access a comprehensive system report exposed through an unprotected REST API endpoint in the Gravity SMTP plugin. The vulnerability affects all versions of the plugin from 2.1.4 and earlier—a window spanning multiple years of deployments—and impacts approximately 100,000 active WordPress installations.
The vulnerability was patched in version 2.1.5, released on March 17, 2026, but the three-month lag between the fix and peak exploitation activity suggests many site administrators have not yet upgraded.
The attack requires no authentication and no interaction from site owners. A simple HTTP GET request to the exposed endpoint /wp-json/gravitysmtp/v1/tests/mock-data returns a JSON "System Report" containing:
## Background and Context
Gravity SMTP is a popular WordPress plugin designed to route WordPress-generated emails through a more reliable third-party email service, ensuring transactional emails (password resets, notifications, user registrations) actually reach recipients. Its wide deployment—100,000 sites—reflects how many WordPress installations struggle with email deliverability.
The vulnerability stems from a misconfigured REST API endpoint where the permission callback is hardcoded to return true, bypassing WordPress's authentication checks entirely. This is a straightforward developer error but one with severe consequences given the sensitivity of the data exposed.
Timeline of Events:
The three-month gap between patch and active exploitation is typical for plugin vulnerabilities. Threat actors either discovered the flaw independently or obtained information about it post-patch and began targeting unpatched installations.
## Technical Details
The attack flow is straightforward and requires minimal technical sophistication:
1. Attacker sends a GET request to the exposed endpoint with the query parameter ?page=gravitysmtp-settings
2. The endpoint's permission check returns true without validating user identity
3. Gravity SMTP generates a full system report and returns it as JSON
4. Attacker receives API credentials, plugin inventory, server details, and database information
Key Indicators of Compromise (IOCs):
Website administrators can identify exploitation attempts by monitoring access logs for:
/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings query parameter/wp-json/gravitysmtp/ pathExploitation Volume:
| Date | Blocked Requests |
|------|------------------|
| June 7 | 4,000,000 |
| June 8–12 | Sustained activity (millions daily) |
| Total blocked | 17,000,000+ |
Wordfence identified the most prolific attacker IP addresses; website administrators should add these to their firewall blocklists to prevent further reconnaissance attempts.
## Implications for Organizations
The exposure of live email service credentials represents both an immediate abuse risk and a reconnaissance advantage for attackers.
### Immediate Risks
### Reconnaissance and Follow-On Attacks
The detailed system report provides attackers with a complete attack surface map:
This reconnaissance data "significantly lowers the effort required to plan further attacks," according to Wordfence researchers, effectively making the target a high-value prospect for secondary exploitation attempts.
## A Broader Pattern: Plugin Vulnerabilities at Scale
The Gravity SMTP incident is not an isolated case. Just one day before Wordfence's warning, the security firm issued a separate advisory about CVE-2026-8713, a critical arbitrary file-deletion flaw in the Avada Builder WordPress plugin (deployed on 1 million sites). That vulnerability allows unauthenticated attackers to delete critical files on the web server, including wp-config.php, leading to full site takeover and remote code execution.
The pattern is clear: high-impact plugin vulnerabilities are being discovered and actively exploited within weeks of patches becoming available. This reflects both the scale of WordPress deployments and the slow update cycles many site administrators maintain.
## Recommendations
For WordPress Site Administrators:
1. Immediate action: Update Gravity SMTP to version 2.1.5 or later immediately. This patch is now three months old, and active exploitation is confirmed.
2. Audit email credentials: Review all third-party email service account activity. Rotate API keys and OAuth tokens for Amazon SES, Google, Mailjet, Resend, and Zoho if the Gravity SMTP plugin is deployed on your site.
3. Review access logs: Search web server logs for the IOC pattern /wp-json/gravitysmtp/v1/tests/mock-data to determine if your site has been probed.
4. Block attacker IPs: Wordfence has published the most prolific source IP addresses; add these to your firewall or WAF blocklist.
5. Implement a plugin update policy: Set WordPress plugins to update automatically or schedule weekly update reviews. Delaying patches by more than 30 days significantly increases breach risk.
For WordPress Security Teams:
1. Monitor for lateral movement: If Gravity SMTP exploitation is detected, investigate for additional compromises on the affected server, particularly exploitation of secondary vulnerabilities.
2. Email credential rotation plan: Establish a process to bulk-rotate credentials for email services across your WordPress installations.
3. Plugin audit: Audit your WordPress plugin inventory for other plugins with known vulnerabilities or plugins from developers with poor security track records.
## HackWire Analysis
The Gravity SMTP exploitation campaign reveals a critical gap in WordPress security: the three-month window between patch release and active exploitation is becoming the norm, not the exception. For attackers, this represents a predictable hunting ground—they can simply monitor plugin release notes, reverse-engineer patches, and then systematically exploit the percentage of sites that haven't updated.
What makes this case particularly alarming is the nature of the exposed data. Stolen API keys and OAuth tokens are not theoretical risks—they are *immediately monetizable*. An attacker with Amazon SES credentials can begin sending phishing or spam within minutes, incurring charges on the victim's account and damaging the organization's sender reputation in ways that take weeks to repair. The reconnaissance data compounds the problem: a site operator's full tech stack is now visible to an attacker, who can then research known vulnerabilities in that specific combination of plugins and versions.
The Avada Builder vulnerability disclosed one day later (CVE-2026-8713) suggests this is not an anomaly. WordPress plugin ecosystem vulnerabilities are being discovered and exploited in an accelerating cycle. Site administrators who treat plugin updates as optional or defer them to a "convenient time" are essentially leaving their sites open for automated reconnaissance and exploitation.
The real story here is one of *scale meeting apathy*. When 100,000 websites run vulnerable code, the economics of exploitation become trivial—even a 1% success rate yields thousands of compromised sites and thousands of dollars in stolen credentials and abused services.
For defenders, the lesson is unambiguous: plugin updates are not hygiene; they are incident response. Sites running Gravity SMTP 2.1.4 or earlier should treat this as a security incident in progress, not a scheduled maintenance item.
— HackWire Editorial
---
## Related Coverage