
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-60062 is an unauthenticated SQL Injection vulnerability in the tPlayer (tplayer-html5-audio-player-with-playlist) WordPress plugin developed by mmetrodw. It affects all versions up to and including 1.2.1.6, with no official patch currently available. The vulnerability was reported by researcher 0xd4rk5id3 on July 16, 2025, and published by Patchstack on August 15, 2025. It carries a CVSS v3.1 base score of 9.4 (Critical) per NVD, and 9.3 (High/Critical) per Patchstack (Patchstack).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input is not properly sanitized before being incorporated into SQL queries within the plugin (Patchstack). Exploitation requires no authentication and no user interaction, with a network-based attack vector and low attack complexity, making it trivially exploitable by remote, unauthenticated attackers. The vulnerability falls under OWASP Top 10 category A3: Injection. No public proof-of-concept code has been disclosed at this time.
Successful exploitation allows an unauthenticated remote attacker to directly interact with the WordPress site's underlying database, enabling theft of sensitive data (e.g., user credentials, personal information), modification or deletion of database records, and potentially unauthorized execution of database operations. The confidentiality and integrity impacts are rated High, with a Low availability impact, indicating the primary risk is data exposure and data manipulation. In a WordPress context, database compromise can lead to full site takeover if administrative credentials are extracted (Patchstack).
No public proof-of-concept exploit or evidence of in-the-wild exploitation has been reported as of the time of publication. The EPSS score is approximately 0.021% (0.000210), indicating a currently low but non-zero probability of exploitation in the near term. Patchstack notes that vulnerabilities of this severity class are frequently used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity, suggesting elevated future risk. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been made (Patchstack).
inurl:/wp-content/plugins/tplayer-html5-audio-player-with-playlist/).sqlmap to automate extraction of database tables, WordPress user credentials (hashed passwords), and other sensitive data from the wp_users and other tables.', --, UNION, SELECT, SLEEP) in query parameters; repeated requests from a single IP to tPlayer-related endpoints.UNION SELECT or time-delay functions (SLEEP, BENCHMARK) originating from WordPress database calls; unauthorized changes to wp_users or other tables.wp-content/plugins/ or wp-content/uploads/, which may indicate post-exploitation webshell deployment.As of the publication date, no official patch from the plugin developer (mmetrodw) is available for tPlayer versions <= 1.2.1.6. The primary recommended action is to immediately disable or remove the tPlayer plugin from affected WordPress installations until a patched version is released. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts in the interim. Additionally, deploying a Web Application Firewall (WAF) with SQL injection detection rules and conducting a database audit for signs of unauthorized access are strongly advised (Patchstack).
Patchstack, which discovered and disclosed the vulnerability through researcher 0xd4rk5id3, has classified it as high priority and noted that vulnerabilities of this type are commonly leveraged in mass-exploit campaigns against WordPress sites. The vulnerability was noted on Bluesky via the CVE feed shortly after publication. No significant broader media coverage or notable researcher commentary beyond Patchstack's advisory has been identified at this time (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."