CVE-2025-60062
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-60062 is an unauthenticated SQL Injection vulnerability in the tPlayer (tplayer-html5-audio-player-with-playlist) WordPress plugin developed by mmetrodw. It affects all versions up to and including 1.2.1.6, with no official patch currently available. The vulnerability was reported by researcher 0xd4rk5id3 on July 16, 2025, and published by Patchstack on August 15, 2025. It carries a CVSS v3.1 base score of 9.4 (Critical) per NVD, and 9.3 (High/Critical) per Patchstack (Patchstack).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input is not properly sanitized before being incorporated into SQL queries within the plugin (Patchstack). Exploitation requires no authentication and no user interaction, with a network-based attack vector and low attack complexity, making it trivially exploitable by remote, unauthenticated attackers. The vulnerability falls under OWASP Top 10 category A3: Injection. No public proof-of-concept code has been disclosed at this time.

Impact

Successful exploitation allows an unauthenticated remote attacker to directly interact with the WordPress site's underlying database, enabling theft of sensitive data (e.g., user credentials, personal information), modification or deletion of database records, and potentially unauthorized execution of database operations. The confidentiality and integrity impacts are rated High, with a Low availability impact, indicating the primary risk is data exposure and data manipulation. In a WordPress context, database compromise can lead to full site takeover if administrative credentials are extracted (Patchstack).

Exploitability

No public proof-of-concept exploit or evidence of in-the-wild exploitation has been reported as of the time of publication. The EPSS score is approximately 0.021% (0.000210), indicating a currently low but non-zero probability of exploitation in the near term. Patchstack notes that vulnerabilities of this severity class are frequently used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity, suggesting elevated future risk. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been made (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the tPlayer plugin (version <= 1.2.1.6) using tools like WPScan, Shodan, or Google dorks targeting the plugin's known file paths (e.g., inurl:/wp-content/plugins/tplayer-html5-audio-player-with-playlist/).
  2. Identify injectable parameter: Probe the plugin's publicly accessible endpoints or shortcode-rendered pages for parameters that interact with the database without authentication.
  3. Craft SQL injection payload: Construct a malicious SQL payload (e.g., using UNION-based, error-based, or time-based blind injection techniques) to be injected into the vulnerable parameter.
  4. Extract database contents: Use tools such as sqlmap to automate extraction of database tables, WordPress user credentials (hashed passwords), and other sensitive data from the wp_users and other tables.
  5. Escalate access: Crack extracted password hashes offline or use the compromised admin credentials to log into the WordPress dashboard, enabling full site takeover, malware installation, or further lateral movement (Patchstack).

Indicators of compromise

  • Network: Unusual HTTP requests to WordPress pages rendering tPlayer shortcodes containing SQL metacharacters (e.g., ', --, UNION, SELECT, SLEEP) in query parameters; repeated requests from a single IP to tPlayer-related endpoints.
  • Logs: WordPress or web server access logs showing requests with encoded or obfuscated SQL syntax targeting plugin endpoints; database error messages in PHP/WordPress debug logs referencing tPlayer queries.
  • Database: Unexpected queries in MySQL slow query logs or general query logs involving UNION SELECT or time-delay functions (SLEEP, BENCHMARK) originating from WordPress database calls; unauthorized changes to wp_users or other tables.
  • File System: Newly created or modified PHP files in the WordPress installation directory, particularly in wp-content/plugins/ or wp-content/uploads/, which may indicate post-exploitation webshell deployment.

Mitigation and workarounds

As of the publication date, no official patch from the plugin developer (mmetrodw) is available for tPlayer versions <= 1.2.1.6. The primary recommended action is to immediately disable or remove the tPlayer plugin from affected WordPress installations until a patched version is released. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts in the interim. Additionally, deploying a Web Application Firewall (WAF) with SQL injection detection rules and conducting a database audit for signs of unauthorized access are strongly advised (Patchstack).

Community reactions

Patchstack, which discovered and disclosed the vulnerability through researcher 0xd4rk5id3, has classified it as high priority and noted that vulnerabilities of this type are commonly leveraged in mass-exploit campaigns against WordPress sites. The vulnerability was noted on Bluesky via the CVE feed shortly after publication. No significant broader media coverage or notable researcher commentary beyond Patchstack's advisory has been identified at this time (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management