← WordPress Vulnerabilities
WordPress security by component

TheGem (Elementor)

TheGem (Elementor) (thegem-elementor) is a WordPress theme with 6 published CVE records in this archive. The latest tracked vulnerability was published Aug 20, 2026; the highest published CVSS base score is 9.3.

Theme slug: thegem-elementor

CVE-2026-66609: TheGem (Elementor) permits unauthenticated SQL injection

TheGem (Elementor) <= 5.12.3 allows an unauthenticated attacker to place crafted input into an SQL query without adequate neutralization. The CVSS vector assigns high confidentiality and low availability impact, indicating database disclosure and query disruption without a separately claimed write primitive.

PublishedAug 20, 2026
Known safe version5.12.3.1
Published vulnerabilities for thegem-elementor
Safe version
Aug 20, 2026 CVE-2026-66609
TheGem (Elementor) permits unauthenticated SQL injection
TheGem (Elementor) <= 5.12.3 allows an unauthenticated attacker to place crafted input into an SQL query without adequate neutralization. The CVSS vector assigns high confidentiality and low availability impact, indicating database disclosure and query disruption without a separately claimed write primitive.
5.12.3.1
CVE9.3
NVDPending
Dec 30, 2025 CVE-2023-32238
TheGem (Elementor): A security weakness
TheGem (Elementor) is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Nov 06, 2025 CVE-2025-62041
TheGem (Elementor): Cross-site scripting
TheGem (Elementor) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Nov 06, 2025 CVE-2025-62012
TheGem (Elementor): Cross-site scripting
TheGem (Elementor) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Sep 26, 2025 CVE-2025-60096
TheGem (Elementor): A security weakness
TheGem (Elementor) is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Mar 26, 2024 CVE-2023-32237
TheGem (Elementor): Cross-site scripting
TheGem (Elementor) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending