medium · CVSS v3 4.3 · EPSS 0.00139
CVE-2026-16557
The Nimble Page Builder plugin for WordPress contains an authorization bypass vulnerability in its AJAX handling logic. This flaw allows any
Overview
The Nimble Page Builder plugin for WordPress contains an authorization bypass vulnerability in its AJAX handling logic. This flaw allows any authenticated user, including those with low-level Subscriber permissions, to view the content of non-public posts such as drafts, private pages, and scheduled content.
Description
The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-builder content of arbitrary non-public (draft, pending, private, scheduled) posts and pages.
Impact
Confidentiality is compromised as unauthorized internal users can disclose sensitive pre-release information or internal documentation stored in drafts. The impact is limited to data disclosure within the WordPress environment and does not allow for data modification or system-level access. Organizations with multi-user environments are at the highest risk of internal information leakage.
Remediation
Update the Nimble Page Builder plugin to the latest available version (greater than 3.3.8) where authorization checks have been implemented. Defenders should also review user roles and consider restricting dashboard access for low-privileged accounts if not required for business operations.
Risk context
The vulnerability is rated as Medium severity with a CVSS v3 score of 4.3. Given the low EPSS score of 0.00139, there is currently a low probability of widespread automated exploitation, though the risk remains pertinent for sites with many untrusted authenticated users.
Affected products
- PressCustomizr Nimble Page Builder <= 3.3.8
- WordPress
Scores
- Severity
- medium
- CVSS v2
- 4
- CVSS v3
- 4.3
- CVSS v4
- —
- EPSS
- 0.00139