# CVE-2026-78152

## Summary

- **CVE ID:** CVE-2026-78152
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **CWE:** N/A
- **Published:** Sep 12, 2026
- **Last Modified:** Sep 12, 2026

## Description

The SureRank SEO  WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.

## Affected Products

- Unknown — SureRank SEO (1.6.2)

## References

- [CNA](https://wpscan.com/vulnerability/f16d3d06-6db0-4c6a-9eee-80b87d886a47/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.24%
- **EPSS Percentile:** 15.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._