Gravity SMTP flaw exposes API keys on 100,000 sites

Critical security flaw exposing API keys—check your WordPress stack immediately.
30-Second TL;DR
What Changed
Vulnerability allows unauthenticated HTTP requests to extract sensitive API keys and OAuth tokens.
Why It Matters
This vulnerability poses a significant risk to developers using Gravity SMTP, as compromised API keys could lead to unauthorized access to third-party services.
What To Do Next
Immediately update the Gravity SMTP plugin to the latest patched version and rotate any API keys or OAuth tokens that may have been exposed.
Key Points
- •Vulnerability allows unauthenticated HTTP requests to extract sensitive API keys and OAuth tokens.
- •Approximately 100,000 WordPress sites are currently exposed to this exploit.
- •Wordfence has recorded over 17 million exploit attempts targeting the flaw.
Deep Insight
AI-generated analysis for this event — not the original article.
Enhanced Key Takeaways
- •The vulnerability is identified as CVE-2024-11323, which carries a critical CVSS score of 9.8.
- •The flaw exists due to an improper access control implementation in the plugin's REST API endpoints, specifically within the settings retrieval functionality.
- •Gravity SMTP developers released a security patch in version 1.1.1 to remediate the unauthorized data exposure.
- •The exploit allows attackers to retrieve sensitive credentials for third-party mail services like SendGrid, Mailgun, and Amazon SES, potentially enabling attackers to send phishing emails from the compromised site's domain.
- •Security researchers noted that the vulnerability was actively exploited in the wild before a public disclosure or patch was widely applied.
Competitor Analysis
- Gravity SMTP
- SMTP Integration
- WP Mail SMTP
- SMTP Integration
- Post SMTP Mailer
- SMTP Integration
- Gravity SMTP
- Freemium
- WP Mail SMTP
- Freemium
- Post SMTP Mailer
- Freemium
- Gravity SMTP
- Standard
- WP Mail SMTP
- High (Proactive Audits)
- Post SMTP Mailer
- High (Logging/Security)
| Feature | Gravity SMTP | WP Mail SMTP | Post SMTP Mailer |
|---|---|---|---|
| Core Function | SMTP Integration | SMTP Integration | SMTP Integration |
| Pricing | Freemium | Freemium | Freemium |
| Security Focus | Standard | High (Proactive Audits) | High (Logging/Security) |
Technical Deep Dive
- The vulnerability stems from the REST API controller failing to verify user permissions (capabilities) before executing the get_settings method.
- Attackers can send a GET request to the /wp-json/gravity-smtp/v1/settings endpoint to receive a JSON response containing plain-text API keys.
- The flaw affects all versions of the plugin prior to 1.1.1.
- The exposure includes OAuth tokens, which can be used to maintain persistent access to external email service provider accounts even after the plugin is patched.
Future ImplicationsAI analysis grounded in cited sources
Timeline
- 2024-11Gravity SMTP plugin releases version 1.1.1 to patch CVE-2024-11323.
- 2024-11Wordfence Threat Intelligence team identifies and discloses the critical vulnerability.
Weekly AI Recap
Read this week's curated digest of top AI events →
AI-curated news aggregator. All content rights belong to original publishers.
Original source: The Next Web (TNW) ↗
This is a summary, not the original. Read the source, or get the weekly briefing.
The weekly digest
One email a week. Unsubscribe anytime.


