Executive brief
SureRank is a popular WordPress SEO plugin that helps websites improve search engine visibility. In versions before 1.10.1, the plugin inadvertently exposed the email addresses of all published authors in publicly viewable structured data (schema markup) on article pages. An attacker could easily harvest email addresses of all content creators, including administrator accounts, without needing to log in or authenticate.
Technical details
The vulnerability is a sensitive data disclosure issue (CWE-200) in the SureRank SEO WordPress plugin. The plugin includes Person schema structured data on published posts by default, but fails to exclude users' registered WordPress email addresses from this output. An unauthenticated attacker can request any published post and extract email addresses directly from the JSON-LD or microdata schema markup via simple HTTP requests and pattern matching. No authentication, special privileges, or user interaction is required—only that the plugin is active with default settings and at least one post exists. The issue was fixed in version 1.10.1. Versions 1.6.2 through 1.10.0 are confirmed vulnerable.
Affected products
- SureRank SureRank SEO 1.6.2 to 1.10.0
Timeline
- 2026-09-10: disclosed
- 2026-09-10: patched: Fixed in version 1.10.1