CVE-2026-78152 PUBLISHED

SureRank 1.6.2 - 1.10.0 - Unauthenticated Author Email Disclosure via Person Schema

Assigner: WPScan
Reserved: 23.08.2026 Published: 12.09.2026 Updated: 12.09.2026

The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.

Product Status

Vendor Unknown
Product SureRank SEO
Versions Default: unaffected
  • affected from 1.6.2 to 1.10.1 (excl.)

Credits

  • Vaibhav Narkhede finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE