SourceStalecollected in 86m

Gravity SMTP flaw exposes API keys on 100,000 sites

Read original on The Next Web (TNW)
#cybersecurity#wordpress-plugin#data-breach

Critical security flaw exposing API keys—check your WordPress stack immediately.

30-Second TL;DR

What Changed

Vulnerability allows unauthenticated HTTP requests to extract sensitive API keys and OAuth tokens.

Why It Matters

This vulnerability poses a significant risk to developers using Gravity SMTP, as compromised API keys could lead to unauthorized access to third-party services.

What To Do Next

Immediately update the Gravity SMTP plugin to the latest patched version and rotate any API keys or OAuth tokens that may have been exposed.

Who should care:Developers & AI Engineers

Key Points

  • •Vulnerability allows unauthenticated HTTP requests to extract sensitive API keys and OAuth tokens.
  • •Approximately 100,000 WordPress sites are currently exposed to this exploit.
  • •Wordfence has recorded over 17 million exploit attempts targeting the flaw.

Deep Insight

AI-generated analysis for this event — not the original article.

Enhanced Key Takeaways

  • •The vulnerability is identified as CVE-2024-11323, which carries a critical CVSS score of 9.8.
  • •The flaw exists due to an improper access control implementation in the plugin's REST API endpoints, specifically within the settings retrieval functionality.
  • •Gravity SMTP developers released a security patch in version 1.1.1 to remediate the unauthorized data exposure.
  • •The exploit allows attackers to retrieve sensitive credentials for third-party mail services like SendGrid, Mailgun, and Amazon SES, potentially enabling attackers to send phishing emails from the compromised site's domain.
  • •Security researchers noted that the vulnerability was actively exploited in the wild before a public disclosure or patch was widely applied.

Competitor Analysis

Core Function
Gravity SMTP
SMTP Integration
WP Mail SMTP
SMTP Integration
Post SMTP Mailer
SMTP Integration
Pricing
Gravity SMTP
Freemium
WP Mail SMTP
Freemium
Post SMTP Mailer
Freemium
Security Focus
Gravity SMTP
Standard
WP Mail SMTP
High (Proactive Audits)
Post SMTP Mailer
High (Logging/Security)

Technical Deep Dive

  • The vulnerability stems from the REST API controller failing to verify user permissions (capabilities) before executing the get_settings method.
  • Attackers can send a GET request to the /wp-json/gravity-smtp/v1/settings endpoint to receive a JSON response containing plain-text API keys.
  • The flaw affects all versions of the plugin prior to 1.1.1.
  • The exposure includes OAuth tokens, which can be used to maintain persistent access to external email service provider accounts even after the plugin is patched.

Future ImplicationsAI analysis grounded in cited sources

Increased scrutiny of WordPress plugin REST API implementations.
High-profile vulnerabilities in REST endpoints are forcing security auditors to prioritize API access control checks in automated scanning tools.
Shift toward mandatory security audits for plugins with high active installation counts.
The scale of this exploit highlights the systemic risk posed by popular plugins that handle sensitive third-party credentials.

Timeline

2024-11
Gravity SMTP plugin releases version 1.1.1 to patch CVE-2024-11323.
2024-11
Wordfence Threat Intelligence team identifies and discloses the critical vulnerability.

Weekly AI Recap

Read this week's curated digest of top AI events →

AI-curated news aggregator. All content rights belong to original publishers.
Original source: The Next Web (TNW) ↗

This is a summary, not the original. Read the source, or get the weekly briefing.

The weekly digest

One email a week. Unsubscribe anytime.