๐Ÿ” CVE Alert

CVE-2026-16557

UNKNOWN 0.0

Nimble Builder <= 3.3.8 - Subscriber+ Non-Public Content Disclosure via sek_get_nimble_content_for_seo_plugins

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-builder content of arbitrary non-public (draft, pending, private, scheduled) posts and pages.

Vendor unknown
Product nimble page builder
Published Sep 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown nimble page builder

Be the first to know when new unknown vulnerabilities affecting unknown nimble page builder are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Nimble Page Builder
0 โ‰ค 3.3.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/a47221d4-bd82-4813-a2de-423fbe014ea0/

Credits

Ayush Gangwar WPScan