WordPress security by component
TheGem (Elementor)
TheGem (Elementor) (thegem-elementor) is a WordPress theme with 6 published CVE records in this archive. The latest tracked vulnerability was published Aug 20, 2026; the highest published CVSS base score is 9.3.
Theme slug:
thegem-elementorLatest vulnerability
CVE-2026-66609: TheGem (Elementor) permits unauthenticated SQL injection
TheGem (Elementor) <= 5.12.3 allows an unauthenticated attacker to place crafted input into an SQL query without adequate neutralization. The CVSS vector assigns high confidentiality and low availability impact, indicating database disclosure and query disruption without a separately claimed write primitive.
| Safe version |
|
||
|---|---|---|---|
| Aug 20, 2026 |
CVE-2026-66609
TheGem (Elementor) permits unauthenticated SQL injection
TheGem (Elementor) <= 5.12.3 allows an unauthenticated attacker to place crafted input into an SQL query without adequate neutralization. The CVSS vector assigns high confidentiality and low availability impact, indicating database disclosure and query disruption without a separately claimed write primitive.
|
5.12.3.1 |
CVE9.3
NVDPending
|
| Dec 30, 2025 |
CVE-2023-32238
TheGem (Elementor): A security weakness
TheGem (Elementor) is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Nov 06, 2025 |
CVE-2025-62041
TheGem (Elementor): Cross-site scripting
TheGem (Elementor) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Nov 06, 2025 |
CVE-2025-62012
TheGem (Elementor): Cross-site scripting
TheGem (Elementor) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Sep 26, 2025 |
CVE-2025-60096
TheGem (Elementor): A security weakness
TheGem (Elementor) is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Mar 26, 2024 |
CVE-2023-32237
TheGem (Elementor): Cross-site scripting
TheGem (Elementor) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|