Input validation vulnerability in TheGem 5.9.1

TheGem theme for WordPress is vulnerable to a security risk known as Reflected Cross-Site Scripting. This risk exists in all versions of TheGem theme up to 5.9.1 and is caused by improper protection against input and output of data. Unauthenticated users can exploit this vulnerability to inject malicious code into web pages that will be executed if they can successfully deceive a user into performing an action, such as clicking a link.

Detected in:

TheGem open vulnerable versions: >= * <= 5.9.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.