Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for WPBakery) thegem-elements.This issue affects TheGem Theme Elements (for WPBakery): from n/a through <= 5.10.5.1.
Published: 2025-11-06
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation allows a malicious actor to inject arbitrary scripts that run in the browsers of visitors to a compromised site. Such cross‑site scripting can lead to credential theft, session hijacking, defacement, or the delivery of additional malware, compromising the confidentiality, integrity, and availability of user data and the site itself.

Affected Systems

The Gem Theme Elements (for WPBakery) plugin by CodexThemes is affected when installed on any WordPress site up to and including version 5.10.5.1. Sites that rely on this plugin for page construction or content rendering are potentially vulnerable if the plugin is left at a version before the fix is released and the site does not apply additional sanitation of user supplied data.

Risk and Exploitability

The stated CVSS score of 6.5 indicates a moderate severity vulnerability. The EPSS score of less than 1% suggests that the probability of observed exploitation is very low, although the vulnerability is still measurable and exploitable. The issue is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is the injection of untrusted input into the plugin’s output rendering process, possibly via administrative interfaces or crafted URLs; an attacker who can supply such data can execute arbitrary script code in the victim’s browser.

Generated by OpenCVE AI on April 29, 2026 at 13:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update CodexThemes TheGem Theme Elements (for WPBakery) to the latest available release that contains the fix. If newer releases are not available, consider removing the plugin from the site or switching to an alternative that is maintained.
  • If an immediate upgrade is not possible, block or sanitize any user input that is passed to the plugin’s output by applying WordPress escaping functions such as esc_html() or esc_attr() to all data that may reach the page.
  • Audit custom code, shortcodes, or page templates that interact with the plugin and enforce strict validation and sanitization to prevent script injection.

Generated by OpenCVE AI on April 29, 2026 at 13:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Fri, 07 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Codexthemes
Codexthemes thegem
Wordpress
Wordpress wordpress
Vendors & Products Codexthemes
Codexthemes thegem
Wordpress
Wordpress wordpress

Thu, 06 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for WPBakery) thegem-elements.This issue affects TheGem Theme Elements (for WPBakery): from n/a through <= 5.10.5.1.
Title WordPress TheGem Theme Elements (for WPBakery) plugin <= 5.10.5.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Codexthemes Thegem
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:50:53.305Z

Reserved: 2025-10-07T15:34:26.392Z

Link: CVE-2025-62044

cve-icon Vulnrichment

Updated: 2025-11-06T20:52:16.687Z

cve-icon NVD

Status : Deferred

Published: 2025-11-06T16:16:10.837

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-62044

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T14:00:12Z

Weaknesses