Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ayush Gangwar

#54712of 57,338
4.3Total CVSS
Vulnerabilities · 1
PT-2026-95751
4.3
2026-09-19
WordPress · Nimble Page Builder · CVE-2026-16557
**Name of the Vulnerable Software and Affected Versions** Nimble Page Builder WordPress plugin versions prior to 3.3.9 **Description** An authorization check is missing when returning page-builder content through an authenticated AJAX action. This allows any authenticated user with Subscriber level permissions or higher to disclose the page-builder content of arbitrary non-public posts and pages, including those with draft, pending, private, or scheduled status. **Recommendations** Update the Nimble Page Builder WordPress plugin to version 3.3.9 or later.