CVE-2026-66609: WordPress TheGem (Elementor) theme <= 5.12.3 - SQL Injection vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
Affected Software
1 affected component
WordPress TheGem (Elementor)<=5.12.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress TheGem (Elementor) themeto a version that resolves this vulnerability.Fixed in 5.12.3.1
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
The issue is unauthenticated, so an attacker does not need a WordPress account or prior access. The network attack vector indicates it can be targeted remotely.
2
Which installations are affected?
The affected product is the WordPress TheGem (Elementor) theme at version 5.12.3 or earlier.
3
What is the potential impact of successful exploitation?
The supplied severity vector indicates high confidentiality impact and low availability impact. Integrity impact is listed as none.