Hackers are actively exploiting a vulnerability in the Gravity SMTP WordPress plugin that exposes API keys, putting website security at risk. The flaw allows attackers to access sensitive authentication credentials that could be used to compromise email systems and other connected services. WordPress site administrators using this plugin are urged to update immediately to protect their API keys from unauthorized access.