CVE-2026-16557
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Sep 19, 2026
Vendor
unknown
Description
The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-builder content of arbitrary non-public (draft, pending, private, scheduled) posts and pages.