Description
The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.
Published: 2026-09-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privacy
Action: Immediate patch
AI Analysis

Impact

The SureRank SEO WordPress plugin fails to filter email addresses from the structured data it places on public pages. As a result, anyone with view access to a page can see the email address of any registered user who has published content. This disclosure can be used for targeted phishing or other social engineering attacks, undermining user privacy and trust in the site.

Affected Systems

WordPress sites that have the SureRank SEO plugin of versions 1.6.2 through 1.10.0 installed. These versions do not filter out email addresses from the structured data output, leading to exposure of all registered users’ emails on visible pages.

Risk and Exploitability

The vulnerability requires no authentication or special privileges, reachable page on the site. The exploit is trivial, employing only a web request. The CVSS score is 5.3, indicating a medium‑severity privacy concern. The EPSS score is less than 1%, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog, but the low barrier to exploitation warrants attention.

Generated by OpenCVE AI on September 13, 2026 at 00:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the SureRank SEO plugin to version 1.10.1 or later
  • If an update cannot be output templates or add a custom filter to remove or mask user email addresses from the structured data before sending it to public pages.
  • If the plugin cannot be kept current and no workaround is available, remove or disable the SureRank SEO plugin entirely to stop the disclosure of email addresses.

Generated by OpenCVE AI on September 13, 2026 at 00:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.
Title SureRank 1.6.2 - 1.10.0 - Unauthenticated Author Email Disclosure via Person Schema
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:34:51.058Z

Reserved: 2026-08-23T06:58:44.956Z

Link: CVE-2026-78152

cve-icon Vulnrichment

Updated: 2026-09-12T15:24:11.230Z

cve-icon NVD

Status : Received

Published: 2026-09-12T06:16:25.290

Modified: 2026-09-12T16:16:39.357

Link: CVE-2026-78152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T01:00:14Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor