<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/hackers-are-mass-exploiting-a-gravity-smtp-flaw-to-steal-api-keys-from-100-000-wordpress-sites-hhj1prnxn" -->

---
title: Hackers are mass-exploiting a Gravity SMTP flaw to steal...
description: A critical unauthenticated information disclosure vulnerability (CVE-2026-4020) in the Gravity SMTP WordPress plugin is being mass-exploited, with Wordfence...
canonical: https://daily.dev/posts/hackers-are-mass-exploiting-a-gravity-smtp-flaw-to-steal-api-keys-from-100-000-wordpress-sites-hhj1prnxn
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Hackers are mass-exploiting a Gravity SMTP flaw to steal API keys from 100,000 WordPress sites | daily.dev
og:description: A critical unauthenticated information disclosure vulnerability (CVE-2026-4020) in the Gravity SMTP WordPress plugin is being mass-exploited, with Wordfence...
og:url: https://daily.dev/posts/hackers-are-mass-exploiting-a-gravity-smtp-flaw-to-steal-api-keys-from-100-000-wordpress-sites-hhj1prnxn
og:image: https://api.daily.dev/og/posts/HhJ1pRnxn.png
og:image:alt: Hackers are mass-exploiting a Gravity SMTP flaw to steal API keys from 100,000 WordPress sites
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Hackers are mass-exploiting a Gravity SMTP flaw to steal API keys from 100,000 WordPress sites

**[The Next Web](https://daily.dev/sources/tnw)** · 5 min read · 0 upvotes · 0 comments

## Summary

A critical unauthenticated information disclosure vulnerability (CVE-2026-4020) in the Gravity SMTP WordPress plugin is being mass-exploited, with Wordfence blocking over 17 million attempts since early May 2026. The flaw, present in all versions through 2.1.4, stems from a REST API endpoint whose permission callback unconditionally returns true, allowing anyone to retrieve ~365 KB of JSON containing API keys, OAuth tokens, and full system configuration data without logging in. Supported email integrations including Amazon SES, Google, Mailjet, Resend, and Zoho are all affected. A patch was released in version 2.1.5 on March 17, 2026, but exploitation peaked around June 7 with over 4 million blocked requests in a single day. Site owners are urged to update immediately and rotate all API credentials, as updating the plugin does not revoke already-stolen keys. A separate critical file-deletion vulnerability (CVE-2026-8713) in the Avada Builder plugin affecting ~1 million sites was also disclosed this week.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thenextweb.com/news/gravity-smtp-wordpress-plugin-vulnerability-cve-2026-4020-api-keys-exploit>

## Similar posts on daily.dev

- [Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin](https://daily.dev/posts/hackers-exploit-info-disclosure-bug-in-gravity-smtp-wordpress-plugin-4vu35e6v7) · BleepingComputer · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#wordpress](https://daily.dev/tags/wordpress)

[View this post on daily.dev](https://daily.dev/posts/hackers-are-mass-exploiting-a-gravity-smtp-flaw-to-steal-api-keys-from-100-000-wordpress-sites-hhj1prnxn)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Hackers are mass-exploiting a Gravity SMTP flaw to steal API keys from 100,000 WordPress sites","url":"https://daily.dev/posts/hackers-are-mass-exploiting-a-gravity-smtp-flaw-to-steal-api-keys-from-100-000-wordpress-sites-hhj1prnxn","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/hackers-are-mass-exploiting-a-gravity-smtp-flaw-to-steal-api-keys-from-100-000-wordpress-sites-hhj1prnxn"},"datePublished":"2026-06-20T17:58:08.560Z","dateModified":"2026-06-20T18:22:28.008Z","description":"A critical unauthenticated information disclosure vulnerability (CVE-2026-4020) in the Gravity SMTP WordPress plugin is being mass-exploited, with Wordfence...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/6e20e57aeec16668360b252b719fac7f?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/6e20e57aeec16668360b252b719fac7f?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The Next Web","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Next Web","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/tnw","url":"https://daily.dev/sources/tnw"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/hackers-are-mass-exploiting-a-gravity-smtp-flaw-to-steal-api-keys-from-100-000-wordpress-sites-hhj1prnxn","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,wordpress","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Next Web","item":"https://daily.dev/sources/tnw"},{"@type":"ListItem","position":3,"name":"Hackers are mass-exploiting a Gravity SMTP flaw to steal API keys from 100,000 WordPress sites"}]}
```

