Authorization Bypass in Nimble Page Builder Plugin by WordPress
CVE-2026-16557
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 19 September 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-16557?
The Nimble Page Builder WordPress plugin, up to version 3.3.8, lacks an authorization check when returning content through an authenticated AJAX action. This oversight allows any authenticated user with a role of Subscriber or higher to access and disclose the content of non-public posts and pages, including drafts, pending, private, and scheduled items, potentially exposing sensitive data.
Affected Version(s)
Nimble Page Builder 0 <= 3.3.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.