Description
The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-builder content of arbitrary non-public (draft, pending, private, scheduled) posts and pages.
Published: 2026-09-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure of non-public content
Action: Update
AI Analysis

Impact

The Nimble Page Builder plugin for WordPress, up to and including version 3.3.8, contains a flaw in its AJAX functionality. When a subscriber or higher‑privileged user makes an authenticated request to the sek_get_nimble_content_for_seo_plugins action, the plugin returns the full content of any post or page regardless of its publication state. This allows a legitimate user to retrieve drafts, pending, private, or scheduled content that should otherwise remain confidential. The vulnerability is rooted in the lack of an authorization check before delivering the content and can be classified as an Information Exposure flaw. Because the content is delivered directly and unfiltered, an attacker can obtain the text, images, and metadata of any protected page or post on the site.

Affected Systems

The affected product is the Nimble Page Builder WordPress plugin. All installations of the plugin with version 3.3.8 or earlier are vulnerable; the vulnerability exists regardless of the WordPress core version or other plugins in use.

Risk and Exploitability

The flaw allows any authenticated user with the Subscriber role or higher to retrieve non‑public page content. Since many sites permit large numbers of subscriber accounts, the risk of widespread exposure is substantial. No public exploit has been disclosed, and the EPSS score is < 1%, but the lack of an authorization guard means the condition for exploitation is simple: authenticate and send the proper AJAX request. The CVSS score is 4.3; the potential impact on confidentiality is significant, and the vulnerability is listed in the CISA KEV catalog as not listed. The attack vector is authenticated internal. The risk should be considered high for sites that rely on privacy of drafts or private posts.

Generated by OpenCVE AI on September 20, 2026 at 00:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Nimble Page Builder to the latest available version (greater than 3.3.8).
  • Restrict the Subscriber role or other roles that can use AJAX actions, removing the capability to trigger sek_get_nimble_content_for_seo_plugins.
  • If possible, delete or disable the vulnerable AJAX endpoint from the plugin’s code or using custom WordPress code removal hooks.

Generated by OpenCVE AI on September 20, 2026 at 00:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions nimble Builder
Vendors & Products Wordpress-extensions
Wordpress-extensions nimble Builder

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Sat, 19 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-builder content of arbitrary non-public (draft, pending, private, scheduled) posts and pages.
Title Nimble Builder <= 3.3.8 - Subscriber+ Non-Public Content Disclosure via sek_get_nimble_content_for_seo_plugins
References

Subscriptions

Wordpress-extensions Nimble Builder
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-19T13:21:13.776Z

Reserved: 2026-07-22T12:04:47.017Z

Link: CVE-2026-16557

cve-icon Vulnrichment

Updated: 2026-09-19T13:13:49.182Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T07:16:32.303

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-16557

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:46Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor