CVE-2026-16557
Received Received - Intake

Unauthorized Page Builder Content Disclosure in WordPress Plugin

Vulnerability report for CVE-2026-16557, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-19

Last updated on: 2026-09-19

Assigner: WPScan

Description

The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-builder content of arbitrary non-public (draft, pending, private, scheduled) posts and pages.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-19
Last Modified
2026-09-19
Generated
2026-09-20
AI Q&A
2026-09-20
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nimble_page_builder plugin 3.3.8

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Nimble Page Builder WordPress plugin up to version 3.3.8. It allows any authenticated user with at least a Subscriber role to access non-public page-builder content from draft, pending, private, or scheduled posts and pages without proper authorization checks.

Detection Guidance

To detect this vulnerability, check for unauthorized access to page-builder content. Use WordPress admin credentials to inspect AJAX requests for the vulnerable action. Look for requests to admin-ajax.php with the action parameter set to nimble_page_builder_get_content.

Impact Analysis

An attacker with a basic user account could view sensitive or unpublished content on your WordPress site, potentially exposing confidential information before it is ready for public release.

Compliance Impact

This vulnerability could lead to unauthorized access to private or sensitive data, which may violate compliance requirements such as GDPR (data protection) or HIPAA (health information privacy) if such data is exposed.

Mitigation Strategies

Immediately update the Nimble Page Builder plugin to the latest version if available. If no update exists, consider disabling the plugin until a patch is released. Restrict user roles to minimize exposure and monitor for unauthorized content access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16557. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart