
CVE-2023-32238 – TheGem < 5.8.1.1 - Improper Authentication
https://notcve.org/view.php?id=CVE-2023-32238
05 May 2023 — The TheGem theme for WordPress is vulnerable to improper authentication in versions up to 5.8.1.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unknown action. • CWE-287: Improper Authentication •

CVE-2023-32237 – Auth. Stored Cross-Site Scripting (XSS) vulnerability in TheGem theme by CodexThemes
https://notcve.org/view.php?id=CVE-2023-32237
05 May 2023 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery) allows Stored XSS.This issue affects TheGem (Elementor): from n/a before 5.8.1.1; TheGem (WPBakery): from n/a before 5.8.1.1. Vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web ('Cross-site Scripting') en CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery) permite almacenar XSS. Este problema ... • https://patchstack.com/database/vulnerability/thegem-elementor/wordpress-thegem-elementor-theme-5-7-2-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •