Impact
The SureRank SEO WordPress plugin fails to filter email addresses from the structured data it places on public pages. This vulnerability represents a CWE-200: anyone with view access to a page can see the email address of any registered user who has published content. This disclosure can be used for targeted phishing or other social engineering attacks, undermining user privacy and trust in the site.
Affected Systems
WordPress sites that have the SureRank SEO plugin of versions 1.6.2 through 1.10.0 installed. These versions do not filter out email addresses from the structured data output, leading to exposure of all registered users’ emails on visible pages.
Risk and Exploitability
The likely attack vector is a simple HTTP GET request to any public page served by the site. The plugin outputs structured data that includes the author’s email address without filtering, so an unauth indicates that no authentication or privileged access is required, which means the exploit is trivial. The CVSS score of 5.3 reflects a medium‑severity privacy issue. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog; nevertheless, the low barrier to exploitation warrants prompt attention.
OpenCVE Enrichment