Executive brief
TheGem, a popular multi-purpose WordPress theme, contains a security vulnerability that allows users with 'Contributor' level access to inject malicious scripts into the website. If an administrator or site visitor views the affected content, these scripts could execute, potentially leading to unauthorized actions, website defacement, or redirection to malicious sites. This risk is particularly relevant for sites that allow multiple users to draft or submit content.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the CodexThemes TheGem theme for WordPress (versions <= 5.11.1). The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with 'Contributor' or higher privileges can inject malicious JavaScript payloads into the site. Successful exploitation requires a victim (such as an administrator) to interact with the affected page or content. This can lead to session hijacking, unauthorized administrative actions, or the delivery of further browser-based exploits. As of the advisory date, no official patch has been confirmed.
Affected products
- CodexThemes TheGem <= 5.11.1
Timeline
- 2026-01-23: disclosed: Reported by João Pedro S Alcântara (Kinorth)
- 2026-07-22: advisory: Patchstack published advisory
- 2026-07-23: other: CVE published to NVD