CVE-2025-60097
Description
Missing Authorization vulnerability in CodexThemes TheGem thegem allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TheGem: from n/a through <= 5.10.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2025-60097 is a missing authorization vulnerability in the WordPress TheGem theme (<=5.10.5) allowing attackers to exploit incorrectly configured access controls.
Vulnerability
CVE-2025-60097 is a missing authorization vulnerability in the WordPress TheGem theme, affecting versions through 5.10.5. The issue stems from the theme's failure to properly enforce access controls, allowing exploitation of incorrectly configured security levels [1]. This type of broken access control can be triggered without authentication, as the theme may not validate user privileges for certain actions.
Exploitation
Attackers can exploit this vulnerability without requiring elevated privileges, as the missing authorization checks allow unauthenticated users to perform actions intended for higher-privileged roles. The vulnerability is accessible via network requests, and no special prerequisites are needed beyond targeting a website running the vulnerable theme [1]. The theme's failure to implement proper nonce tokens or capability checks exacerbates the risk.
Impact
Successful exploitation could enable an attacker to execute actions that should be restricted to administrators, such as modifying theme settings or accessing sensitive information. This could lead to partial loss of integrity and confidentiality, but no direct privilege escalation is guaranteed beyond the scope of the broken access control.
Mitigation
The vendor has addressed this vulnerability in a version beyond 5.10.5; users are strongly advised to update to the latest available version immediately [1]. No workarounds are documented, and the vulnerability has been exploited in mass campaigns, highlighting the urgency of patching.
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <= 5.10.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.