Impact
The Nimble Page Builder plugin for WordPress, up to and including version 3.3.8, contains a flaw in its AJAX functionality. When a subscriber or higher‑privileged user makes an authenticated request to the sek_get_nimble_content_for_seo_plugins action, the plugin returns the full content of any post or page regardless of its publication state. This allows a legitimate user to retrieve drafts, pending, private, or scheduled content that should otherwise remain confidential. The vulnerability is rooted in the lack of an authorization check before delivering the content and can be classified as an Information Exposure flaw. Because the content is delivered directly and unfiltered, an attacker can obtain the text, images, and metadata of any protected page or post on the site.
Affected Systems
The affected product is the Nimble Page Builder WordPress plugin. All installations of the plugin with version 3.3.8 or earlier are vulnerable; the vulnerability exists regardless of the WordPress core version or other plugins in use.
Risk and Exploitability
The flaw allows any authenticated user with the Subscriber role or higher to retrieve non‑public page content. Since many sites permit large numbers of subscriber accounts, the risk of widespread exposure is substantial. No public exploit has been disclosed, and the EPSS score is < 1%, but the lack of an authorization guard means the condition for exploitation is simple: authenticate and send the proper AJAX request. The CVSS score is 4.3; the potential impact on confidentiality is significant, and the vulnerability is listed in the CISA KEV catalog as not listed. The attack vector is authenticated internal. The risk should be considered high for sites that rely on privacy of drafts or private posts.
OpenCVE Enrichment