Executive brief
TheGem is a popular WordPress theme that provides page-building functionality through Elementor. An unauthenticated SQL injection vulnerability allows attackers without any credentials to read, modify, or delete the entire database, including user accounts and customer data. This vulnerability is critical because it requires no authentication and can be exploited at scale against thousands of websites simultaneously.
Technical details
The vulnerability is a SQL injection flaw in TheGem (Elementor) theme versions 5.12.3 and earlier, allowing unauthenticated attackers to execute arbitrary SQL queries. The vulnerability is network-accessible and requires no authentication or user interaction to exploit. Successful exploitation enables attackers to read, modify, or delete database content including user accounts, private customer data, and site configuration. The issue has been patched in version 5.12.3.1 and later; users should update immediately to mitigate risk.
Affected products
- CodexThemes TheGem (Elementor) <= 5.12.3
Timeline
- 2026-08-20: disclosed
- 2026-08-19: patched: Patched in version 5.12.3.1