CodexThemes TheGem Theme Elements PHP Local File Inclusion Vulnerability

Vulnerability

A vulnerability allowing PHP local file inclusion has been identified in CodexThemes TheGem Theme Elements for Elementor, versions prior to and including 5.11.0. This issue arises from improper control of filenames in include or require statements, potentially leading to unauthorized access to local files on the server.

Impact

Exploitation of this vulnerability could allow an attacker to include local files through PHP's include or require functions, which could be used to execute arbitrary PHP code or read sensitive files on the server.

Added: Jan 6, 2026, 5:20 PM
Updated: Jan 6, 2026, 5:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
1.9
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.