Back to all lessons
Awareness Lessons
4 months ago

Unpatched Gravity SMTP Plugin Leaks API Keys via Unauthenticated REST Endpoint

The Gravity SMTP WordPress plugin contained a flaw (CVE-2026-4020) that exposed a REST API endpoint to unauthenticated users, allowing attackers to retrieve sensitive credentials including API keys, secrets, and OAuth tokens without any login. The root issue is a failure to enforce authentication controls on an endpoint that should never be publicly accessible. This matters because exposed API keys and OAuth tokens can lead to full account takeovers, data breaches, and lateral movement across connected third-party services. Although a patch exists in version 2.1.5, active exploitation before widespread patching demonstrates how quickly threat actors weaponize even medium-severity disclosures.

Tactical Insight

Immediate actions

  • Update the Gravity SMTP plugin to version 2.1.5 or later on all WordPress installations immediately.
  • Audit and rotate any API keys, OAuth tokens, and secrets that may have been exposed through the vulnerable endpoint.
  • Block known malicious IP addresses identified in exploit attempts at the web application firewall (WAF) or hosting firewall level.

Long-term improvements

  • Implement an automated vulnerability scanning process that monitors installed WordPress plugins against known CVE databases on a continuous basis.
  • Enforce a policy requiring authentication and least-privilege access controls on all REST API endpoints before deployment.
  • Maintain a complete, up-to-date inventory of all installed plugins and their versions to accelerate emergency patching response.

Detection measures

  • Enable logging of all REST API requests and alert on unauthenticated access attempts to sensitive endpoints.
  • Deploy a Web Application Firewall (WAF) rule set to detect and block anomalous REST API enumeration patterns.
  • Integrate threat intelligence feeds to receive early warning of active exploit campaigns targeting your plugin stack.