Cross-site Scripting Vulnerability in CodexThemes TheGem Product
CVE-2025-62041

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 November 2025

What is CVE-2025-62041?

A Cross-site Scripting (XSS) vulnerability in CodexThemes' TheGem (Elementor) allows attackers to inject harmful scripts into web pages rendered for users. This flaw affects TheGem versions up to 5.10.5.1 and poses significant risks as it can enable malicious users to execute arbitrary scripts in the context of a user’s session, leading to potential theft of sensitive information or session hijacking. Website administrators are advised to secure their installations and update to the latest version to mitigate this risk.

Affected Version(s)

TheGem (Elementor) <= n/a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program
.
CVE-2025-62041 : Cross-site Scripting Vulnerability in CodexThemes TheGem Product