THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-78152 (MEDIUM 5.3) — The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.

[NVD] CVE-2026-78152 (MEDIUM 5.3) — The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.

mednvdPublished 2026-09-12

CVE-2026-78152 CVSS: 5.3 MEDIUM Published: 2026-09-12T06:16:25.290

The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-78152