PatchSiren cyber security CVE debrief
CVE-2026-8938 nakamura1458 CVE debrief
A Cross-Site Request Forgery (CSRF) vulnerability in the Auto Making JSON-LD WordPress plugin allows unauthenticated attackers to manipulate license settings and trigger unauthorized pro feature installation. The flaw exists in the `amJL_certification` function due to missing or incorrect nonce validation, affecting all versions up to and including 4.5.3. Successful exploitation requires social engineering an administrator into clicking a malicious link, but the downstream impact extends beyond simple settings modification to include license validation checks and automatic installation of plugin components.
- Vendor
- nakamura1458
- Product
- auto making JSON-LD
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-05-27
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-05-27
Who should care
WordPress site administrators using the Auto Making JSON-LD plugin; security teams monitoring plugin supply chain integrity; organizations with strict software installation policies
Technical summary
The vulnerability resides in the `amJL_certification` function within the Auto Making JSON-LD WordPress plugin. Missing nonce validation permits unauthenticated attackers to forge requests that update the plugin's license key option. This triggers subsequent calls to `amJL_is_license_valid()` and `amJL_download_and_install_pro_features()`, enabling unauthorized pro feature installation without administrator consent. The attack requires user interaction through social engineering.
Defensive priority
medium
Recommended defensive actions
- Update Auto Making JSON-LD plugin to version 4.5.4 or later when available
- Implement additional CSRF protection layers via web application firewall rules for WordPress admin endpoints
- Review plugin file integrity and audit recently installed components if exploitation is suspected
- Apply principle of least privilege for WordPress administrator accounts
- Monitor for unexpected plugin installations or license validation network traffic
Evidence notes
Vulnerability confirmed via WordPress plugin repository source code review at certification.php lines 14 and 16. Wordfence assigned CVE and published technical analysis. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N reflects network attack vector with user interaction required.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8938 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8938
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8938 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8938
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/auto-making-json-ld/tags/4.5.3/settings/certification.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/auto-making-json-ld/tags/4.5.3/settings/certification.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.