CVE-2026-16557
Nimble Builder <= 3.3.8 - Subscriber+ Non-Public Content Disclosure via sek_get_nimble_content_for_seo_plugins
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-builder content of arbitrary non-public (draft, pending, private, scheduled) posts and pages.
| Vendor | unknown |
| Product | nimble page builder |
| Published | Sep 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown nimble page builder
Be the first to know when new unknown vulnerabilities affecting unknown nimble page builder are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Nimble Page Builder
0 โค 3.3.8
References
Credits
Ayush Gangwar WPScan