WordPress Plugin Vulnerabilities

Nimble Builder <= 3.3.8 - Subscriber+ Non-Public Content Disclosure via sek_get_nimble_content_for_seo_plugins

Description

The plugin does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-builder content of arbitrary non-public (draft, pending, private, scheduled) posts and pages.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Ayush Gangwar
Submitter
Ayush Gangwar
Verified
Yes

Timeline

Publicly Published
2026-09-16 (about 2 days ago)
Added
2026-09-09 (about 9 days ago)
Last Updated
2026-09-09 (about 9 days ago)

Other