TheGem < 5.8.1.1 - Improper Authentication

2023-05-05 00:00
Dave Jong

Strategic Overview

Status
Patched in 5.8.1.1
Affected ThemeTheGem
Affected Version< 5.8.1.1
CVSS6.3Medium
CVECVE-2023-32238
View all TheGem vulnerabilities

Vulnerability Overview

The TheGem theme for WordPress is vulnerable to improper authentication in versions up to 5.8.1.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unknown action.

Technical Analysis

REMEDIATION: Update to version 5.8.1.1, or a newer patched version --- IDENTIFIER: CWE-287 (Improper Authentication) When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C