Impact
TheGem theme for WordPress contains a missing capability check in its ajaxApi function, which allows authenticated users with Subscriber level or higher to update arbitrary theme options. This flaw, classified as a Missing Authorization weakness, can alter site appearance or redirect users without the site owner's consent, compromising the integrity of the theme configuration.
Affected Systems
The vulnerability affects all CodexThemes:TheGem WordPress theme releases up to and including version 5.10.3. Any site utilizing these theme versions is susceptible; newer releases are not affected as they contain the missing authorization check fix.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation. Because the flaw requires a valid authenticated account at the Subscriber level or higher and operates via an AJAX endpoint, the attack vector is restricted to inbound authenticated web requests. The vulnerability is not listed in the CISA KEV catalog, further indicating it may not be a high‑profile threat at present.
OpenCVE Enrichment
EUVD