# Gravity SMTP Plugin Flaw Exposes API Keys and Secrets on 100,000 WordPress Sites


A critical information disclosure vulnerability in the widely-deployed Gravity SMTP WordPress plugin is being actively exploited by threat actors to steal email service credentials and reconnaissance data from tens of thousands of websites. Security firm Wordfence has blocked over 17 million exploitation attempts against its protected customers, signaling a rapid and sustained attack campaign targeting the flaw.


## The Threat


CVE-2026-4020, rated as medium severity, allows unauthenticated attackers to access a comprehensive system report exposed through an unprotected REST API endpoint in the Gravity SMTP plugin. The vulnerability affects all versions of the plugin from 2.1.4 and earlier—a window spanning multiple years of deployments—and impacts approximately 100,000 active WordPress installations.


The vulnerability was patched in version 2.1.5, released on March 17, 2026, but the three-month lag between the fix and peak exploitation activity suggests many site administrators have not yet upgraded.


The attack requires no authentication and no interaction from site owners. A simple HTTP GET request to the exposed endpoint /wp-json/gravitysmtp/v1/tests/mock-data returns a JSON "System Report" containing:


  • Email service credentials for integrations including Amazon SES, Google Workspace, Mailjet, Resend, and Zoho
  • Live API keys and OAuth tokens for third-party email services
  • Complete WordPress inventory: installed plugins, active themes, software versions
  • Server and database information: PHP version, database engine, table names
  • Site configuration details that reveal the site's technical footprint

  • ## Background and Context


    Gravity SMTP is a popular WordPress plugin designed to route WordPress-generated emails through a more reliable third-party email service, ensuring transactional emails (password resets, notifications, user registrations) actually reach recipients. Its wide deployment—100,000 sites—reflects how many WordPress installations struggle with email deliverability.


    The vulnerability stems from a misconfigured REST API endpoint where the permission callback is hardcoded to return true, bypassing WordPress's authentication checks entirely. This is a straightforward developer error but one with severe consequences given the sensitivity of the data exposed.


    Timeline of Events:

  • March 17, 2026: Patch released in version 2.1.5
  • June 7, 2026: Exploitation activity spikes to 4 million blocked requests in a single day
  • June 7–12, 2026: Sustained exploitation activity recorded across multiple days
  • June 19, 2026: Wordfence and Defiant issue public warnings

  • The three-month gap between patch and active exploitation is typical for plugin vulnerabilities. Threat actors either discovered the flaw independently or obtained information about it post-patch and began targeting unpatched installations.


    ## Technical Details


    The attack flow is straightforward and requires minimal technical sophistication:


    1. Attacker sends a GET request to the exposed endpoint with the query parameter ?page=gravitysmtp-settings

    2. The endpoint's permission check returns true without validating user identity

    3. Gravity SMTP generates a full system report and returns it as JSON

    4. Attacker receives API credentials, plugin inventory, server details, and database information


    Key Indicators of Compromise (IOCs):


    Website administrators can identify exploitation attempts by monitoring access logs for:

  • Requests to /wp-json/gravitysmtp/v1/tests/mock-data
  • Requests containing the ?page=gravitysmtp-settings query parameter
  • Unusual spike in 404s to the /wp-json/gravitysmtp/ path

  • Exploitation Volume:


    | Date | Blocked Requests |

    |------|------------------|

    | June 7 | 4,000,000 |

    | June 8–12 | Sustained activity (millions daily) |

    | Total blocked | 17,000,000+ |


    Wordfence identified the most prolific attacker IP addresses; website administrators should add these to their firewall blocklists to prevent further reconnaissance attempts.


    ## Implications for Organizations


    The exposure of live email service credentials represents both an immediate abuse risk and a reconnaissance advantage for attackers.


    ### Immediate Risks


  • Email service abuse: Stolen Amazon SES, Google, or Zoho credentials can be used to send phishing emails, spam, or malware at the victim organization's expense, damaging the organization's sender reputation and email deliverability.
  • Account impersonation: Attackers can assume the identity of the affected organization when communicating with third-party email services, making it difficult for the legitimate owner to regain control.
  • Cost impact: Compromised email service accounts may be used for large-scale spam campaigns, resulting in unexpected bills and service suspension.

  • ### Reconnaissance and Follow-On Attacks


    The detailed system report provides attackers with a complete attack surface map:


  • Plugin inventory reveals which plugins are installed, allowing attackers to research known vulnerabilities in the site's specific tech stack
  • WordPress version enables targeting of version-specific exploits
  • Database information reveals the database engine and configuration, useful for planning SQL injection or database-level attacks
  • Server and PHP details guide exploitation strategy (e.g., which PHP functions are available, which extensions are loaded)

  • This reconnaissance data "significantly lowers the effort required to plan further attacks," according to Wordfence researchers, effectively making the target a high-value prospect for secondary exploitation attempts.


    ## A Broader Pattern: Plugin Vulnerabilities at Scale


    The Gravity SMTP incident is not an isolated case. Just one day before Wordfence's warning, the security firm issued a separate advisory about CVE-2026-8713, a critical arbitrary file-deletion flaw in the Avada Builder WordPress plugin (deployed on 1 million sites). That vulnerability allows unauthenticated attackers to delete critical files on the web server, including wp-config.php, leading to full site takeover and remote code execution.


    The pattern is clear: high-impact plugin vulnerabilities are being discovered and actively exploited within weeks of patches becoming available. This reflects both the scale of WordPress deployments and the slow update cycles many site administrators maintain.


    ## Recommendations


    For WordPress Site Administrators:


    1. Immediate action: Update Gravity SMTP to version 2.1.5 or later immediately. This patch is now three months old, and active exploitation is confirmed.

    2. Audit email credentials: Review all third-party email service account activity. Rotate API keys and OAuth tokens for Amazon SES, Google, Mailjet, Resend, and Zoho if the Gravity SMTP plugin is deployed on your site.

    3. Review access logs: Search web server logs for the IOC pattern /wp-json/gravitysmtp/v1/tests/mock-data to determine if your site has been probed.

    4. Block attacker IPs: Wordfence has published the most prolific source IP addresses; add these to your firewall or WAF blocklist.

    5. Implement a plugin update policy: Set WordPress plugins to update automatically or schedule weekly update reviews. Delaying patches by more than 30 days significantly increases breach risk.


    For WordPress Security Teams:


    1. Monitor for lateral movement: If Gravity SMTP exploitation is detected, investigate for additional compromises on the affected server, particularly exploitation of secondary vulnerabilities.

    2. Email credential rotation plan: Establish a process to bulk-rotate credentials for email services across your WordPress installations.

    3. Plugin audit: Audit your WordPress plugin inventory for other plugins with known vulnerabilities or plugins from developers with poor security track records.


    ## HackWire Analysis


    The Gravity SMTP exploitation campaign reveals a critical gap in WordPress security: the three-month window between patch release and active exploitation is becoming the norm, not the exception. For attackers, this represents a predictable hunting ground—they can simply monitor plugin release notes, reverse-engineer patches, and then systematically exploit the percentage of sites that haven't updated.


    What makes this case particularly alarming is the nature of the exposed data. Stolen API keys and OAuth tokens are not theoretical risks—they are *immediately monetizable*. An attacker with Amazon SES credentials can begin sending phishing or spam within minutes, incurring charges on the victim's account and damaging the organization's sender reputation in ways that take weeks to repair. The reconnaissance data compounds the problem: a site operator's full tech stack is now visible to an attacker, who can then research known vulnerabilities in that specific combination of plugins and versions.


    The Avada Builder vulnerability disclosed one day later (CVE-2026-8713) suggests this is not an anomaly. WordPress plugin ecosystem vulnerabilities are being discovered and exploited in an accelerating cycle. Site administrators who treat plugin updates as optional or defer them to a "convenient time" are essentially leaving their sites open for automated reconnaissance and exploitation.


    The real story here is one of *scale meeting apathy*. When 100,000 websites run vulnerable code, the economics of exploitation become trivial—even a 1% success rate yields thousands of compromised sites and thousands of dollars in stolen credentials and abused services.


    For defenders, the lesson is unambiguous: plugin updates are not hygiene; they are incident response. Sites running Gravity SMTP 2.1.4 or earlier should treat this as a security incident in progress, not a scheduled maintenance item.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)