Impact
The Gem Theme Elements (for Elementor) plugin allows attackers to inject malicious script into web pages due to improper neutralization of input during page rendering. This flaw, classified as CWE‑79, enables the delivery of arbitrary client‑side code that can steal session data, redirect users, or deface content. The impact is limited to the victim’s browser session and is executed client‑side, but it can compromise user data and trust in the site.
Affected Systems
All installations of CodexThemes TheGem Theme Elements (for Elementor) plugin up to and including version 5.10.5.1 are affected, with no specific lower bound listed. The vulnerability applies to every instance of the plugin where user‑supplied or editable data is rendered without proper sanitization.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% suggests a low exploitation probability. The flaw is not currently listed in the CISA KEV catalog. Attackers would need to craft a payload that reaches the plugin’s output rendering process, which could be done via publicly accessible pages or through the admin interface if the plugin outputs untrusted content. No additional conditions or elevated privileges are required for exploitation.
OpenCVE Enrichment