SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-78152

MEDIUM · CVSS 5.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The SureRank SEO WordPress plugin prior to version 1.10.1 exposes registered users' email addresses in structured data on public pages, enabling unauthenticated visitors to access this sensitive information. This vulnerability poses a significant privacy risk, particularly for users who have published content on affected sites. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data exposure.

CVE
CVE-2026-78152
Severity
MEDIUM
CVSS
5.3
EPSS
0.24%
WordPress

Original NVD Description

The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.