Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem (Elementor) thegem-elementor.This issue affects TheGem (Elementor): from n/a through <= 5.10.5.
Published: 2025-11-06
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Gem (Elementor) theme contains an XSS flaw caused by insufficient sanitization of data that is subsequently injected into a page’s output. An attacker can craft input that is stored in theme options, widget content, or other editable fields and that is rendered without escaping, thereby causing arbitrary JavaScript to run in the browsers of visitors to affected pages. This could allow session hijacking, credential theft, or defacement of user‑facing content.

Affected Systems

CodexThemes TheGem (Elementor) theme for WordPress, all releases up through version 5.10.5, including the 5.10.5 snapshot and all earlier minor revisions.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 % suggests a low likelihood of active exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The description indicates that the flaw arises from unsanitized user input that the theme renders, so the most probable attack vector is through any user‐editable content that the theme outputs; however, the specific affected fields are not enumerated in the advisory, so site operators must audit all places where the theme accepts and displays input without applying proper escaping.

Generated by OpenCVE AI on April 29, 2026 at 23:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the TheGem (Elementor) theme to the newest release that fixes the XSS issue.
  • If an upgrade is not immediately possible, disable any theme features that permit users to insert raw HTML or JavaScript, or limit such content to a sanitized subset.
  • Configure a Content Security Policy that disallows inline scripts and restricts script sources to trusted origins, which will block the execution of injected JavaScript on the site.

Generated by OpenCVE AI on April 29, 2026 at 23:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Fri, 07 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Nov 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Codexthemes
Codexthemes thegem
Elementor
Elementor elementor
Wordpress
Wordpress wordpress
Vendors & Products Codexthemes
Codexthemes thegem
Elementor
Elementor elementor
Wordpress
Wordpress wordpress

Thu, 06 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem (Elementor) thegem-elementor.This issue affects TheGem (Elementor): from n/a through <= 5.10.5.
Title WordPress TheGem (Elementor) theme <= 5.10.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Codexthemes Thegem
Elementor Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:47:04.273Z

Reserved: 2025-10-07T15:34:03.910Z

Link: CVE-2025-62012

cve-icon Vulnrichment

Updated: 2025-11-07T14:07:34.755Z

cve-icon NVD

Status : Deferred

Published: 2025-11-06T16:16:08.130

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-62012

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T23:15:23Z

Weaknesses