CodexThemes TheGem Broken Access Control Vulnerability

Vulnerability

A broken access control vulnerability has been identified in CodexThemes TheGem versions prior to 5.8.1.1, affecting both the Elementor and WPBakery page builder integrations. This vulnerability allows unauthorized users to bypass access controls, potentially leading to unauthorized actions or data exposure.

Impact

Exploitation of this vulnerability could allow unauthorized users to gain access to restricted functionalities or data, depending on the specific context of the access control failure.

Added: Dec 30, 2025, 12:22 AM
Updated: Dec 30, 2025, 12:22 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
1.3
exploitability
5.4
remediation
0.0
relevance
1.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.