TheGem <= 5.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The TheGem theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will...
- CVSS:
- 6.4
- Affected:
- up to 5.11.1
- Fix:
- No patched version reported
- Disclosed:
- Jul 22, 2026
CVE-2026-65480 on NVD →
TheGem [thegem] <= 5.10.5 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem thegem.This issue affects TheGem: from n/a through <= 5.10.5.
- Affected:
- up to 5.10.5
- Fix:
- No patched version reported
- Disclosed:
- Nov 6, 2025
CVE-2025-62011 on NVD →
TheGem <= 5.10.5 - Missing Authorization
medium
The TheGem theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.10.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 5.10.5
- Fixed in:
- 5.10.5.1
- Disclosed:
- Sep 26, 2025
CVE-2025-60097 on NVD →
TheGem [thegem] < 5.10.5.1
unknown
[en] Missing Authorization vulnerability in CodexThemes TheGem allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects TheGem: from n/a through 5.10.5.
- Affected:
- up to 5.10.5.1
- Fixed in:
- 5.10.5.1
- Disclosed:
- Sep 26, 2025
CVE-2025-60097 on NVD →
TheGem <= 5.10.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The TheGem theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.10.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will...
- CVSS:
- 6.4
- Affected:
- up to 5.10.5
- Fixed in:
- 5.10.5.1
- Disclosed:
- Sep 3, 2025
CVE-2025-62011 on NVD →
TheGem <= 5.10.3 - Authenticated (Subscriber+) Arbitrary File Upload
high
The TheGem theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the thegem_get_logo_url() function in all versions up to, and including, 5.10.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affe...
- CVSS:
- 8.8
- Affected:
- up to 5.10.3
- Fixed in:
- 5.10.3.1
- Disclosed:
- May 12, 2025
CVE-2025-4317 on NVD →
TheGem <= 5.10.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Theme Options Update
medium
The TheGem theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajaxApi() function in all versions up to, and including, 5.10.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary theme options.
- CVSS:
- 4.3
- Affected:
- up to 5.10.3
- Fixed in:
- 5.10.3.1
- Disclosed:
- May 12, 2025
CVE-2025-4339 on NVD →
TheGem [thegem] < 5.8.1.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery) allows Stored XSS.This issue affects TheGem (Elementor): from n/a before 5.8.1.1; TheGem (WPBakery): from n/a before 5.8.1.1.
- Affected:
- up to 5.8.1.1
- Fixed in:
- 5.8.1.1
- Disclosed:
- Mar 26, 2024
CVE-2023-32237 on NVD →
TheGem [thegem] < 5.9.2
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem - Creative Multi-Purpose & WooCommerce WordPress Theme allows Reflected XSS.This issue affects TheGem - Creative Multi-Purpose & WooCommerce WordPress Theme: from n/a through 5.9.1.
- Affected:
- up to 5.9.2
- Fixed in:
- 5.9.2
- Disclosed:
- Dec 29, 2023
CVE-2023-50892 on NVD →
TheGem <= 5.9.1 - Reflected Cross-Site Scripting
medium
The TheGem theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 5.9.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if th...
- CVSS:
- 6.1
- Affected:
- up to 5.9.1
- Fixed in:
- 5.9.2
- Disclosed:
- Dec 26, 2023
CVE-2023-50892 on NVD →
TheGem < 5.8.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The TheGem theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 5.8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber-level permissions and above to inject arbitrary web scripts in pages that will execute when...
- CVSS:
- 6.4
- Affected:
- up to 5.8.1.1
- Fixed in:
- 5.8.1.1
- Disclosed:
- May 5, 2023
CVE-2023-32237 on NVD →
TheGem < 5.8.1.1 - Missing Authorization
medium
The TheGem theme for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability check on the ajaxApi() function called via an AJAX action in versions up to 5.8.1.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform several...
- CVSS:
- 6.3
- Affected:
- up to 5.8.1.1
- Fixed in:
- 5.8.1.1
- Disclosed:
- May 5, 2023
CVE-2023-32238 on NVD →
TheGem < 5.8.1.1 - Improper Authentication
medium
The TheGem theme for WordPress is vulnerable to improper authentication in versions up to 5.8.1.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unknown action.
- CVSS:
- 6.3
- Affected:
- up to 5.8.1.1
- Fixed in:
- 5.8.1.1
- Disclosed:
- May 5, 2023
CVE-2023-32238 on NVD →
TheGem [thegem] < 5.8.1.1
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 5.8.1.1
- Fixed in:
- 5.8.1.1
CVE-2023-32238 on NVD →
TheGem [thegem] < 5.10.3.1
unknown
- Affected:
- up to 5.10.3.1
- Fixed in:
- 5.10.3.1
CVE-2025-4339 on NVD →
TheGem [thegem] < 5.10.3.1
unknown
- Affected:
- up to 5.10.3.1
- Fixed in:
- 5.10.3.1
CVE-2025-4317 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database