VYPR
Medium severity6.5NVD Advisory· Published Nov 6, 2025· Updated Apr 15, 2026

CVE-2025-62044

CVE-2025-62044

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for WPBakery) thegem-elements.This issue affects TheGem Theme Elements (for WPBakery): from n/a through <= 5.10.5.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in TheGem Theme Elements for WPBakery allows privileged users to inject malicious scripts on WordPress sites.

The vulnerability is a stored cross-site scripting (XSS) flaw in the WordPress plugin 'TheGem Theme Elements (for WPBakery)', version 5.10.5.1 and earlier. It arises from improper neutralization of input during web page generation, allowing attackers who are authenticated with certain privileges to inject arbitrary web scripts or HTML into pages.

Exploitation requires a privileged user to perform an action, such as clicking a malicious link, visiting a crafted page, or submitting a form. The attack does not necessarily require direct interaction from the victim but relies on a privileged user to trigger the injection. Once triggered, the malicious payload is stored and executed when other users access the affected page.

Successful exploitation enables an attacker to inject malicious scripts, such as redirects, advertisements, or other HTML payloads, which are executed in the browsers of visitors to the site. This can lead to defacement, data theft, or phishing attacks. The CVSS v3 score of 6.5 indicates a medium severity.

The vendor has released a patched version 5.10.5.2 to resolve the vulnerability. Administrators are advised to update the plugin immediately. Patchstack users can enable auto-updates for vulnerable plugins to streamline the process. As this issue is used in mass-exploit campaigns, prompt remediation is recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.