theme

Thegem Vulnerabilities

16 known security issues reported for the Thegem WordPress theme. Most recent disclosed Jul 22, 2026.

1 high 8 medium

Running Thegem on your site? Check whether your installed version is affected.

Scan your site free

TheGem <= 5.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The TheGem theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will...

CVSS:
6.4
Affected:
up to 5.11.1
Fix:
No patched version reported
Disclosed:
Jul 22, 2026

CVE-2026-65480 on NVD →

TheGem [thegem] <= 5.10.5 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem thegem.This issue affects TheGem: from n/a through <= 5.10.5.

Affected:
up to 5.10.5
Fix:
No patched version reported
Disclosed:
Nov 6, 2025

CVE-2025-62011 on NVD →

TheGem <= 5.10.5 - Missing Authorization

medium

The TheGem theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.10.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 5.10.5
Fixed in:
5.10.5.1
Disclosed:
Sep 26, 2025

CVE-2025-60097 on NVD →

TheGem [thegem] < 5.10.5.1

unknown

[en] Missing Authorization vulnerability in CodexThemes TheGem allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects TheGem: from n/a through 5.10.5.

Affected:
up to 5.10.5.1
Fixed in:
5.10.5.1
Disclosed:
Sep 26, 2025

CVE-2025-60097 on NVD →

TheGem <= 5.10.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The TheGem theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.10.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will...

CVSS:
6.4
Affected:
up to 5.10.5
Fixed in:
5.10.5.1
Disclosed:
Sep 3, 2025

CVE-2025-62011 on NVD →

TheGem <= 5.10.3 - Authenticated (Subscriber+) Arbitrary File Upload

high

The TheGem theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the thegem_get_logo_url() function in all versions up to, and including, 5.10.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affe...

CVSS:
8.8
Affected:
up to 5.10.3
Fixed in:
5.10.3.1
Disclosed:
May 12, 2025

CVE-2025-4317 on NVD →

TheGem <= 5.10.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Theme Options Update

medium

The TheGem theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajaxApi() function in all versions up to, and including, 5.10.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary theme options.

CVSS:
4.3
Affected:
up to 5.10.3
Fixed in:
5.10.3.1
Disclosed:
May 12, 2025

CVE-2025-4339 on NVD →

TheGem [thegem] < 5.8.1.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery) allows Stored XSS.This issue affects TheGem (Elementor): from n/a before 5.8.1.1; TheGem (WPBakery): from n/a before 5.8.1.1.

Affected:
up to 5.8.1.1
Fixed in:
5.8.1.1
Disclosed:
Mar 26, 2024

CVE-2023-32237 on NVD →

TheGem [thegem] < 5.9.2

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem - Creative Multi-Purpose & WooCommerce WordPress Theme allows Reflected XSS.This issue affects TheGem - Creative Multi-Purpose & WooCommerce WordPress Theme: from n/a through 5.9.1.

Affected:
up to 5.9.2
Fixed in:
5.9.2
Disclosed:
Dec 29, 2023

CVE-2023-50892 on NVD →

TheGem <= 5.9.1 - Reflected Cross-Site Scripting

medium

The TheGem theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 5.9.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if th...

CVSS:
6.1
Affected:
up to 5.9.1
Fixed in:
5.9.2
Disclosed:
Dec 26, 2023

CVE-2023-50892 on NVD →

TheGem < 5.8.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The TheGem theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 5.8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber-level permissions and above to inject arbitrary web scripts in pages that will execute when...

CVSS:
6.4
Affected:
up to 5.8.1.1
Fixed in:
5.8.1.1
Disclosed:
May 5, 2023

CVE-2023-32237 on NVD →

TheGem < 5.8.1.1 - Missing Authorization

medium

The TheGem theme for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability check on the ajaxApi() function called via an AJAX action in versions up to 5.8.1.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform several...

CVSS:
6.3
Affected:
up to 5.8.1.1
Fixed in:
5.8.1.1
Disclosed:
May 5, 2023

CVE-2023-32238 on NVD →

TheGem < 5.8.1.1 - Improper Authentication

medium

The TheGem theme for WordPress is vulnerable to improper authentication in versions up to 5.8.1.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unknown action.

CVSS:
6.3
Affected:
up to 5.8.1.1
Fixed in:
5.8.1.1
Disclosed:
May 5, 2023

CVE-2023-32238 on NVD →

TheGem [thegem] < 5.8.1.1

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 5.8.1.1
Fixed in:
5.8.1.1

CVE-2023-32238 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database