Your WordPress Site Just Leaked Its Keys: AI Makes That Exploit Even Worse

You wouldn’t leave a spare key under the doormat in 2026. However, yet, over 100,000 WordPress sites just did exactly that.

On March 30, Wordfence disclosed CVE-2026-4020 in Gravity SMTP, a plugin used to route email safely through WordPress. The flaw lets unauthenticated attackers pull configuration data, API keys, secrets, and OAuth tokens straight out of your site. The patch shipped months ago. Active exploitation is happening right now, confirmed by Wordfence, CrowdSec, and the WIU Cybersecurity Center on June 20, 2026.

That means your email provider token, your SMTP credentials, and possibly other plugin secrets are sitting in an attacker’s spreadsheet.

Why AI Changes the Stakes

Key theft used to mean manual phishing emails or slow credential-stuffing. In 2026, those stolen keys are weaponised at scale using AI.

Here is the math that should worry you: World Economic Forum data released at Davos 2026 found 87 percent of global executives now call AI-related vulnerabilities the fastest-growing cyber risk. Enterprises scaled generative AI across workflows 18 to 24 months faster than their security governance could catch up. Only one in three organisations deployed AI tools with no prior security validation.

Right now, an attacker with a fresh batch of API keys can use AI to craft personalised, context-aware phishing faster than a human operations team can respond. A leaked Gravity SMTP token gives them a legitimate-looking sender. A generative AI tool writes the follow-up email in perfect context. The victim clicks. That is not hypothetical. That is the current threat model.

Three Things to Do Today

First, check whether Gravity SMTP is active in your WordPress plugins. If it is, confirm it is patched. Wordfence said the patch is available; update immediately.

Second, rotate any API keys or OAuth tokens that pass through your WordPress email stack. Do not reuse the old ones anywhere else.

Third, audit which of your connected services actually need WordPress email routing. The more services tied to one plugin, the larger the blast radius if it leaks. If you do not need SMTP integration, remove it.

For site owners, plugin updates should happen the same day they are released. If you are running a business site, let that sink in: a single patched plugin is the difference between a clean audit and a data breach claim under your insurer’s cyber policy.

Enterprise AI deployment is now 18 to 24 months ahead of mature AI security governance. Attackers are exploiting that gap with stolen credentials and AI-generated social engineering. That is where we are right now.

Related Reading

Subscribe

Related articles

NVIDIA, Microsoft, Meta, and 50+ Companies Tell Washington Not to Lock Down Open AI

More than 50 tech companies including NVIDIA, Microsoft, Meta, and Google published a joint letter urging Washington to protect open-weight AI models. The only notable holdout? Anthropic. Here is what the fight is actually about.

Europe Just Drew a Red Line on AI and Cybersecurity. Here Is What It Means

The EU Action Plan on Cybersecurity and AI sets nine actions across three pillars, with enforcement starting 2 August 2026. Fines climb to 3% of global turnover or 15 million euros for non-compliance. Here is what every security leader needs to know.

Australia Sets Rules for AI. The Hard Part Comes Next.

Australian writers, musicians and journalists will keep ownership of...

FLUX 3: How Black Forest Labs Is Bridging Video AI and Real-World Robots

Black Forest Labs' FLUX 3 is expanding from video and image generation into robot control for Audi factories, with an open-weight model planned for factory hardware.

The Open Source AI Revolution: When the World’s Biggest Models Became Free

Chinese open-source AI models led by Moonshot Kimi K3 have functionally closed the gap with proprietary systems from OpenAI and Anthropic, with profound consequences for geopolitics, global markets, and the future of autonomous AI agents.