TheGem - Creative Multi-Purpose & WooCommerce WordPress Theme

TheGem - Creative Multi-Purpose & WooCommerce WordPress Theme has 13 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; 12 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.2, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 3 high. 2025 was the busiest year with 7 disclosures.

The most common weakness is Cross-Site Scripting, behind 6 of the records (46%). Other recurring categories include Missing Authorization, Improper Authentication.

12 of the records (92%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.

6 independent researchers contributed these findings, most of them (5) reported by Rafie Muhammad.

Strategic Overview

Avg CVSSMedium
6.2/ 10
Patch Coverage92%
Open

1

Fixed

12

Get automatic notifications for all TheGem - Creative Multi-Purpose & WooCommerce WordPress Theme vulnerabilities before they are exploited.

Most severe open issueCVSS 6.4CVE-2026-65480

TheGem <= 5.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

13 records
2026-08-19 00:00CVE-2026-66609
7.5
High
dutafiYes
2026-07-22 00:00CVE-2026-65480
6.4
Medium
João Pedro S Alcântara (Kinorth)No
2025-10-12 00:00CVE-2025-62041
7.2
High
João Pedro Soares de AlcântaraYes
2025-09-26 00:00CVE-2025-60097
4.3
Medium
Rafie MuhammadYes
2025-09-26 00:00CVE-2025-60096
4.3
Medium
Rafie MuhammadYes
2025-09-03 00:00CVE-2025-62011
6.4
Medium
Rafie MuhammadYes
2025-09-03 00:00CVE-2025-62012
6.4
Medium
Rafie MuhammadYes
2025-05-12 18:13CVE-2025-4317
8.8
High
FoxyyyYes
2025-05-12 00:00CVE-2025-4339
4.3
Medium
FoxyyyYes
2023-12-26 00:00CVE-2023-50892
6.1
Medium
Rafie MuhammadYes
Showing 1–10 of 13 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C