Impact
The SureRank SEO WordPress plugin fails to filter email addresses from the structured data it places on public pages. As a result, anyone with view access to a page can see the email address of any registered user who has published content. This disclosure can be used for targeted phishing or other social engineering attacks, undermining user privacy and trust in the site.
Affected Systems
WordPress sites that have the SureRank SEO plugin of versions 1.6.2 through 1.10.0 installed. These versions do not filter out email addresses from the structured data output, leading to exposure of all registered users’ emails on visible pages.
Risk and Exploitability
The vulnerability requires no authentication or special privileges, reachable page on the site. The exploit is trivial, employing only a web request. The CVSS score is 5.3, indicating a medium‑severity privacy concern. The EPSS score is less than 1%, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog, but the low barrier to exploitation warrants attention.
OpenCVE Enrichment