CVE-2023-32237: Codexthemes Thegem Elementor

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery) allows Stored XSS.This issue affects TheGem (Elementor): from n/a before 5.8.1.1; TheGem (WPBakery): from n/a before 5.8.1.1.

Affected products

  • Codexthemes Thegem Elementor: before 5.8.1.1 (fixed in 5.8.1.1)
  • Codexthemes Thegem Wpbakery: before 5.8.1.1 (fixed in 5.8.1.1)

Published 2024-03-26. Last modified 2026-06-17.