Hackers have exploited a vulnerability in the Gravity SMTP WordPress plugin to expose API keys from affected websites. The security flaw allows attackers to access sensitive authentication credentials that could enable further compromise of compromised systems. Users of the plugin are advised to update to the latest patched version immediately.