---
cve: "CVE-2026-78152"
severity: "MEDIUM"
cvss: 5.3
epss: "5.5%"
vendor: "WordPress"
kev: false
exploited: false
published: "2026-09-12 06:16:25"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-16T21:18:17+02:00"
---

# CVE-2026-78152

> 5.3 MEDIUM

## Beschreibung

The SureRank SEO  WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://wpscan.com/vulnerability/f16d3d06-6db0-4c6a-9eee-80b87d886a47/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-78152) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
