CVE-2026-78152: SureRank 1.6.2 - 1.10.0 - Unauthenticated Author Email Disclosure via Person Schema
Published Sep 12, 2026
·Updated
The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.
Affected Software
1 affected component
SureRank SureRank SEO WordPress plugin<1.10.1
Event History
Sep 12, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can retrieve the exposed email addresses?
Any unauthenticated visitor can obtain them from structured data on public pages. The affected users are those who have published content.
2
Are default plugin settings affected?
Yes. The plugin outputs registered account email addresses in structured data on public pages by default.
3
Which versions need remediation?
SureRank versions 1.6.2 through 1.10.0 are affected. Version 1.10.1 is not described as affected.