Impact
Unauthenticated SQL Injection in the WordPress TheGem (Elementor) Theme enables an attacker to inject arbitrary SQL through a vulnerable query handling routine. This flaw can lead to unauthorized data read, modification, and potentially database compromise, as described by the associated CWE-89 error. The vulnerability may also allow escalation of privileges if the attacker can modify data that controls site configuration or user accounts.
Affected Systems
The affected product is the WordPress TheGem (Elementor) Theme provided by CodexThemes. All theme releases up to and including version 5.12.3 are vulnerable. The latest released version, 5.12.3.1, contains the fix.
Risk and Exploitability
With a CVSS score of 9.3 the flaw is considered critical. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, but the high severity and unauthenticated nature make it a prime candidate for exploitation. The likely attack vector is through unrestricted HTTP requests to the theme’s back‑end, where malicious input can be injected without login credentials.
OpenCVE Enrichment