Description
The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.
Published: 2026-09-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privacy
Action: Immediate patch
AI Analysis

Impact

The SureRank SEO WordPress plugin fails to filter email addresses from the structured data it places on public pages. This vulnerability represents a CWE-200: anyone with view access to a page can see the email address of any registered user who has published content. This disclosure can be used for targeted phishing or other social engineering attacks, undermining user privacy and trust in the site.

Affected Systems

WordPress sites that have the SureRank SEO plugin of versions 1.6.2 through 1.10.0 installed. These versions do not filter out email addresses from the structured data output, leading to exposure of all registered users’ emails on visible pages.

Risk and Exploitability

The likely attack vector is a simple HTTP GET request to any public page served by the site. The plugin outputs structured data that includes the author’s email address without filtering, so an unauth indicates that no authentication or privileged access is required, which means the exploit is trivial. The CVSS score of 5.3 reflects a medium‑severity privacy issue. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog; nevertheless, the low barrier to exploitation warrants prompt attention.

Generated by OpenCVE AI on September 15, 2026 at 18:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the SureRank SEO plugin to version 1.10.1 or later
  • If no update is available, configure the plugin to hide or exclude author email addresses from the structured data before it is sent to public pages
  • If the plugin cannot be kept current and no workaround is available, remove or disable the SureRank SEO plugin entirely to stop the disclosure of email addresses

Generated by OpenCVE AI on September 15, 2026 at 18:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.
Title SureRank 1.6.2 - 1.10.0 - Unauthenticated Author Email Disclosure via Person Schema
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:34:51.058Z

Reserved: 2026-08-23T06:58:44.956Z

Link: CVE-2026-78152

cve-icon Vulnrichment

Updated: 2026-09-12T15:24:11.230Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:25.290

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-78152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:00:15Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor