CVE-2026-16557: Nimble Builder <= 3.3.8 - Subscriber+ Non-Public Content Disclosure via sek_get_nimble_content_for_seo_plugins
The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-builder content of arbitrary non-public (draft, pending, private, scheduled) posts and pages.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user with at least the Subscriber role can exploit it. An attacker does not need permission to view the targeted draft, pending, private, or scheduled post or page.
What information may be exposed?
The issue can disclose page-builder content from arbitrary non-public posts and pages, including drafts, pending content, private content, and scheduled content.
How can I determine whether my site is affected?
Sites using the Nimble Page Builder WordPress plugin version 3.3.8 or earlier are affected according to the available information. The vulnerable functionality is the authenticated AJAX action sek_get_nimble_content_for_seo_plugins.