Small Business SEO904-447-0750Take a Test Drive
About100K AI WebsiteGuidesBlogReviewsFAQsContact904-447-0750Take a Test Drive

WordPress · Updates · Small Business

Your WordPress Site Could Be Hacked Right Now. Here's the Fix.

A plugin on 100,000 WordPress sites got its fix in March. Attackers were still hammering it in June, four million tries in a single day. They keep trying because they know how many sites never installed it.

I drive a black cylinder stamped SECURITY BOLT toward a huge circular blue-lit vault door badged with the WordPress logo while a Barred Rock hen screams open-beaked across the front of the frame. Your WordPress site could be hacked right now.

Bob has a red badge on his WordPress dashboard right now.

It has been there a while. He noticed it in the spring. He was going to deal with it, then a job ran long, then it was Friday, then it was just part of the furniture. It sits up in the corner with a little number on it and he stopped seeing it about four weeks ago.

Here is what that badge actually is. Somebody found a hole in a piece of software running on his site. They told the company. The company fixed it and shipped the fix. The fix is sitting on his screen waiting for one click.

And here is the part that should get your attention. The attackers know about that badge too. They know roughly how many people click it and how many do not. That is why they keep attacking holes that were already fixed months ago.

I can show you exactly what that looks like, because one plugin left a paper trail.

This is the plugin that carries your leads. It was handing out the keys with them.

"There's a patch" and "I'm patched" are two different sentences.

Only one of them is about you.

TL;DR (the short answer)

Yes, your WordPress site could be exposed right now to a hole that already has a fix. Gravity SMTP, a plugin on 100,000 WordPress sites, had a flaw tracked as CVE-2026-4020 that let anyone read a full system report from the site, including live email service credentials. It was fixed in version 2.1.5 on March 17, 2026. Attacks against it kept climbing after the fix and peaked on June 7, when Wordfence blocked 4 million requests in a single day, out of more than 17 million blocked in total. Those are attempts, not hacked sites. The fix is to find out what version you run and get the update applied.

3 Things to Remember

1
A fix that exists and a fix that is installed are not the same thing, and only one of them protects you.
2
Attackers keep hitting patched holes on purpose, because they know most sites are slow to update.
3
The plugin that emails you your leads can also hand over the keys to your email service.

The Plugin That Mails You Your Leads Was Leaking Your Keys.

I haul a red valve wheel shut on a steel mail drum that is throwing out wax sealed envelopes and gold keys, with a hen bursting through the spill behind a tumbling envelope. The plugin mailing your leads was leaking your keys.

Gravity SMTP is a WordPress plugin on 100,000 sites. Its whole job is boring and important: make sure the mail from your website actually arrives instead of landing in a spam folder. Every lead you get from your contact form goes through something like it.

The flaw is tracked as CVE-2026-4020 and rated medium. (BleepingComputer, 2026) I want to be straight with you about that rating. This one is not a site takeover. It is a data exposure, and the difference matters.

Here is the plain version of what went wrong. The plugin had an address on your site that would hand back a full system report to anybody who asked. No login. The check that was supposed to decide who was allowed to ask always answered yes.

That report was not a small thing. It could include API keys, secrets and login tokens for your email services, credentials for Amazon SES, Google, Mailjet, Resend and Zoho, your full list of plugins and themes with version numbers, your server and PHP details, and your database setup including table names. (Wordfence via BleepingComputer, 2026)

Sit with the first item on that list. Somebody who takes the keys to your email service can send mail as you, to your customers, from your address.

The mistake: thinking a medium rating means it is not your problem.

The fix: read what the flaw actually exposes, not just the number next to it.

The payoff: you spend your worry on the right things instead of all of them.

The Fix Shipped in March. The Attacks Peaked in June.

The patch was already out. The wave kept building anyway.

Gravity SMTP fixed this in version 2.1.5, released March 17. All versions from 2.1.4 and older were affected. (BleepingComputer, 2026)

That is a fast, clean response. The problem was found, the fix shipped, and site owners had everything they needed in March.

Then look at what happened next.

Wordfence blocked more than 17 million attempts against that flaw. Exploitation spiked on June 7, when 4 million requests were blocked in a single day, and stayed high for several days after. (Wordfence via BleepingComputer, 2026)

June 7 is 82 days after the fix shipped.

17 million

tries blocked against a hole that already had a fix. That is attempts, not hacked sites. There is a difference and I am not going to blur it. (Wordfence via BleepingComputer, 2026)

4 million

requests blocked in one day, June 7, 2026. That was the peak, and it stayed heavy for days afterward. (Wordfence via BleepingComputer, 2026)

82

days between the fix shipping on March 17 and the attacks peaking on June 7. (BleepingComputer, 2026)

Nobody throws four million requests at a door they think is locked. They did it because it works often enough to be worth doing. That is the whole lesson in this post, and it is not really about one plugin.

The fix shipped in March. They were still trying in June.

Here Is Everything Standing Between You and That Update.

One click at the end. This is everything in front of it.

One click. That is the honest answer, and that is also the problem.

Here is the whole list of what has to happen for a patch to reach your site.

  • Somebody has to notice the badge.
  • That somebody has to be the person with the login.
  • They have to trust that the update will not break the site, because one of them did once.
  • They have to do it before an attacker gets there.
  • Then it happens again next month, and the month after, forever.

Every single step on that list is a person with a truck and a jobs list, between calls.

Plenty of sites never got that update at all. Some have automatic updates switched off because something broke once and nobody wanted a repeat. Some are pinned to an old version by a theme or a page builder that will not run on the new one. Some are managed by a guy who stopped answering the phone two years ago.

I laid out what the babysitting actually costs you over three years in the WordPress bill nobody adds up, and why the plugin pile holds you hostage even when you want to clean it out.

The mistake: treating "there is a patch" and "I am patched" like they are the same sentence.

The fix: get it in writing who applies your updates and how often, and ask them for the date of the last one.

The payoff: you stop finding out about your own website from a stranger.

The update was there the whole time. It just needed somebody to press it.

How to Tell If Your Site Was One of Them.

I aim a blue scanning lamp across a wet floor at a black server cabinet marked with the WordPress logo, lighting up a red glowing crack in its face, a caged red alarm beacon burning at my left and a hen flaring its wings under the sign. Was your site one of them?

You can check this yourself, and you should.

Find your version. Log into WordPress, open Plugins, and find Gravity SMTP if you have it. Look at the version number. If it is 2.1.4 or lower, you were exposed and you still are until you update.

Check your logs for the fingerprint. Wordfence named the giveaway: requests to /wp-json/gravitysmtp/v1/tests/mock-data in your web server access logs, especially with ?page=gravitysmtp-settings on the end. (Wordfence via BleepingComputer, 2026) If your host gives you access logs, search for that. If you do not know how, that exact sentence is what you send to your host's support.

If you find it, rotate your keys. This is the step people skip. If that report went out, the credentials in it went with it. Updating the plugin closes the door. It does not change the locks. Go into your email service and generate new keys.

That third one is worth saying plainly. Patching stops the leak. It does not un-leak what already left.

Do it yourself

Find Every Update Sitting On Your Site Right Now

Open your WordPress dashboard, go to Plugins, and copy the list with the version numbers. Paste it in and hit a button. Claude or ChatGPT tells you which ones are behind, which ones had 2026 security fixes, and what order to do them in. Takes about two minutes.

Prompt · What am I behind on
You are a plain-talking website helper. Here is every plugin on my WordPress site with the version I am running: [PASTE YOUR PLUGIN LIST WITH VERSIONS].

Give me one simple table, worst first.
1) The plugin name and my version.
2) The newest version available today.
3) How far behind I am, in plain words.
4) Whether that plugin had a security fix in 2025 or 2026, and what the fix version was.
5) A plain-English note on what that plugin is allowed to do on my site: send email, save files, write to the database, or handle logins.

Then give me two short lists. The updates to do today, and the ones that can wait. For anything involving email or logins, tell me whether I should also change my keys or passwords after updating, and why.

Rules: short sentences, 5th grade words. If you cannot confirm a version, say so instead of guessing.

Paste your plugin list where it says PASTE YOUR PLUGIN LIST WITH VERSIONS. The version numbers are on the same screen.

You get: a worst-first list of what is behind on your own site, and a straight answer on whether updating is enough or whether you also need new keys.

I Didn't Just Write About It. I Left.

This is not a number off somebody's chart. I moved 1,300+ of my own posts off a dying WordPress stack, and the red badge went with it.

I have built more than 10,000 sites in 25 years. I have been the guy who logged in on a Sunday to apply somebody else's update because they were on a roof. I have also been the guy who had to explain why a site went down after an update nobody tested. Both of those weekends are gone from my life now.

You are reading one of those rebuilt pages right now. There is no badge on it, because there is nothing on it waiting for me to click.

A Site With No Update Screen Has Nothing to Miss.

I shove a long steel roller down a blue lit machine corridor running under lit WordPress, Wix and Squarespace panels while a hen lunges in from the right and bites at the bar. A site with no update screen has nothing to miss.

The reason my builds do not have this problem is boring. There is no pile of other people's software on your site, updating on their schedule and waiting on you.

A WordPress site pulls its parts from a dozen companies, and each one ships changes whenever it likes. Your job, forever, is to be the person who notices. That is a maintenance contract nobody told you that you signed.

The sites I build are already built. The pages are finished files sitting on a fast network. Nothing on the page is phoning home to a stranger's server asking what to run next.

That is not me being clever. It is fewer moving parts, so there is less to keep current. That is the whole idea behind the 100K Website, and it is why I say the old machine is done for real business sites.

And when something does need attention, that is my job. You go run your business.

Where Gravity SMTP Actually Did Its Job.

I run a heavy steel key shaft through a round vault hatch toward a lit WordPress boiler standing over a night delivery line of parcels, with a hen filling the right of the frame. Where Gravity SMTP actually did its job.

I will give the developer full credit here, and you should weigh it before you take my side.

They shipped the fix in 2.1.5 on March 17. (BleepingComputer, 2026) They did not sit on it, they did not argue about the severity, and site owners had a working patch in hand months before the attacks peaked. Wordfence then published the indicator so owners could search their own logs for it. Every part of that chain did what it was supposed to do.

And the flaw itself is a medium rated data exposure, not a takeover. It did not hand anybody your admin account.

Now the turn. All of that good work went into a system whose last step is a small business owner noticing a red dot between jobs. The researchers found it, the developer fixed it, the security company published it, and then the whole thing sat on Bob's dashboard for 82 days while four million requests a day went looking for the sites where it was still sitting.

That is not a plugin problem. That is the model.

Your website should not have a to-do list.

You have enough of those. The one thing standing between your site and a hole somebody already fixed should not be whether you happened to look at a corner of a screen this week.

Let me show you what a site with nothing to update actually feels like, built on your own market.

Take a Test Drive →

You get a real look at your own market. No obligation, and nothing to cancel.

Want the whole playbook first? Plan your attack. Balls Out Marketing.

FAQ

Could my WordPress site be hacked right now?

If you are running a plugin version with a known unpatched hole, yes, and the most common reason is an update that shipped months ago and never got installed. Gravity SMTP is the clearest example from 2026: fixed on March 17, still under 4 million attacks a day on June 7.

What is CVE-2026-4020?

It is the tracking number for a flaw in the Gravity SMTP WordPress plugin, rated medium. An open address on the site handed a full system report to anyone who asked, with no login. That report could include live email service credentials, plugin and theme versions, and database details. It was fixed in version 2.1.5 on March 17, 2026.

Do 17 million attacks mean 17 million sites got hacked?

No. That figure is blocked attempts, not compromised sites. It tells you how hard attackers were trying, not how often they succeeded. I will not write it any other way.

Why do attackers target holes that already have a patch?

Because plenty of sites never install it. A published fix tells an attacker exactly where the hole is and exactly what to send. The only thing standing between them and a site is whether somebody clicked update.

Is it enough to just update the plugin?

Not always. If the flaw exposed credentials, updating closes the hole but does not change the keys that already went out. For Gravity SMTP, generate new keys in your email service after updating.

How do I check if my site was attacked?

Ask your host for your web server access logs and search for requests to /wp-json/gravitysmtp/v1/tests/mock-data, especially with ?page=gravitysmtp-settings on the end. That is the fingerprint Wordfence published.

How often do WordPress plugins need updating?

Whenever the plugin ships a security fix, which is not on a schedule you control. In the first quarter of 2026 alone, 2,738 WordPress vulnerabilities were added to Wordfence's database. That is the pace you are keeping up with.

This is post 4 in a run on WordPress security. Post 1 covered the July 2026 hole in WordPress core that needed no password. Post 2 covered the buyer who bought 30 plugins and shipped a backdoor to all of them. Post 3 covered the contact form that let strangers upload files. This one is about the gap between a fix existing and a fix being installed.

Check Out My Last 3 Builds

Real sites, built with this exact system. Tap any one and poke around.

Two Men and a Truck
Moving company
See it live →
Learn Euphoria
Education & courses
See it live →
SoFresh
Fast-casual food
See it live →
Small Business SEO · Jacksonville, FL · Go Balls Out.

Get 2 Must-Read Resources Every Week

No spam. No pitch. Just 2 Must Read Resources a Week.

By downloading, you agree to our Privacy Policy. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.