---
id: CVE-2026-78152
title: >-
  The SureRank SEO  WordPress plugin before 1.10.1 does not exclude users'
  registered account email addresses from the structured data it outputs on
  public pages by default, allowing unauthenticated visitors to obtain the email
  address of …
summary: >-
  The SureRank SEO  WordPress plugin before 1.10.1 does not exclude users'
  registered account email addresses from the structured data it outputs on
  public pages by default, allowing unauthenticated visitors to obtain the email
  address of …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
product: SureRank SEO
affected:
  - surerank_seo >= 1.6.2 < 1.10.1
published: '2026-09-12'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T21:10:17.423'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78152'
references:
  - url: 'https://wpscan.com/vulnerability/f16d3d06-6db0-4c6a-9eee-80b87d886a47/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.0024
epssPercentile: 0.15428
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-12T15:25:33.662607Z'
ingestedAt: '2026-09-14T15:23:07.478Z'
---

## Overview

The SureRank SEO  WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
