VYPR

Nimble Page Builder

by WordPress

CVEs (2)

  • CVE-2022-0314MedApr 11, 2022
    risk 0.40cvss 6.1epss 0.01

    The Nimble Page Builder WordPress plugin before 3.2.2 does not sanitise and escape the preview-level-guid parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

  • CVE-2026-16557MedSep 19, 2026
    risk 0.28cvss 4.3epss 0.00

    The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-builder content of arbitrary non-public…