Attackers Abuse Gravity SMTP WordPress Flaw to Harvest API Keys
A vulnerability in the Gravity SMTP WordPress plugin allowed unauthenticated actors to extract API keys and configuration data from roughly 100,000 sites. A fix is available in version 2.1.5; site owners should update and rotate credentials.