Impact
TheGem theme contains an improper neutralization of input during web page generation, allowing cross‑site scripting. An attacker can inject malicious JavaScript into pages rendered by the theme, potentially leading to session hijacking, credential theft, defacement, or malware delivery. This weakness maps to CWE‑79 and has a CVSS score of 6.5.
Affected Systems
CodexThemes’ TheGem theme from version n/a through 5.10.5 is affected. Any install of the theme using those releases is vulnerable; newer releases beyond 5.10.5 are not listed as impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1 % suggests low probability of exploitation at this time. The vulnerability is not yet listed in the CISA KEV catalog, but because it is an XSS flaw that can be triggered by arbitrary user input, it is likely exploitable by any visitor to a site running the vulnerable theme. Attacks could be carried out remotely by submitting specially crafted data that is then rendered by the theme, executing attacker‑controlled scripts in the victim’s browser.
OpenCVE Enrichment