Cross-site Scripting Vulnerability in CodexThemes TheGem Product
CVE-2025-62041
Currently unrated
What is CVE-2025-62041?
A Cross-site Scripting (XSS) vulnerability in CodexThemes' TheGem (Elementor) allows attackers to inject harmful scripts into web pages rendered for users. This flaw affects TheGem versions up to 5.10.5.1 and poses significant risks as it can enable malicious users to execute arbitrary scripts in the context of a user’s session, leading to potential theft of sensitive information or session hijacking. Website administrators are advised to secure their installations and update to the latest version to mitigate this risk.
Affected Version(s)
TheGem (Elementor) <= n/a