Urgent: Gravity SMTP Plugin Vulnerability Exposed – Update Now

A serious vulnerability in the Gravity SMTP plugin, used by around 100,000 WordPress sites, has been disclosed. This flaw enables unauthenticated attackers to access sensitive information, including API keys and OAuth tokens. The patched version (2.1.5) was released on March 17, 2026, and users must update immediately to avoid potential breaches.

Details of the Gravity SMTP Vulnerability

The vulnerability allows attackers to exploit a REST API endpoint that returns sensitive system configuration data without authentication. This includes crucial details such as PHP version, database server type, and API keys for email integrations. The ease of exploitation-simply sending a GET request-makes this a high-risk situation for site owners.

Recommended Actions

Site owners should update to Gravity SMTP version 2.1.5 without delay. Additionally, consider implementing security measures such as a firewall to further protect against potential attacks. Regularly monitoring your site for unusual activity is also advisable.

Scale of Exploits

The Wordfence Firewall has blocked over 17 million exploit attempts targeting this vulnerability, indicating a significant level of active exploitation. The spike in attacks highlights the urgency for users to secure their sites promptly.

Frequently Asked Questions

What versions of Gravity SMTP are affected by the vulnerability?

Versions of Gravity SMTP up to and including 2.1.4 are affected.

When was the patched version of Gravity SMTP released?

The patched version, Gravity SMTP 2.1.5, was released on March 17, 2026.

How many exploit attempts have been blocked by Wordfence?

The Wordfence Firewall has blocked over 17 million exploit attempts targeting this vulnerability.

What sensitive data can be accessed due to this vulnerability?

Attackers can access sensitive data including API keys, OAuth tokens, and detailed system configuration information.