Input validation vulnerability in TheGem 5.8.1.1

TheGem theme for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting (XSS). This vulnerability exists in all versions up to 5.8.1.1 and is caused by the theme not properly sanitizing user input nor escaping output. This means that attackers, who have access to the website with a subscriber-level account or higher, can inject malicious code into pages which will be executed every time a user visits them.

Detected in:

TheGem open vulnerable versions: > 0 < 0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.