{"id":"CVE-2026-78152","title":"The SureRank SEO  WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of …","summary":"The SureRank SEO  WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of …","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-200"],"product":"SureRank SEO","affected":["surerank_seo >= 1.6.2 < 1.10.1"],"published":"2026-09-12","updated":"2026-09-14","sourceUpdated":"2026-09-14T21:10:17.423","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-78152","references":[{"url":"https://wpscan.com/vulnerability/f16d3d06-6db0-4c6a-9eee-80b87d886a47/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"epss":0.0024,"epssPercentile":0.15419,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-12T15:25:33.662607Z"},"ingestedAt":"2026-09-14T15:23:07.478Z","slug":"CVE-2026-78152","body":"## Overview\n\nThe SureRank SEO  WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}