CVE-2023-5070
MEDIUMUltimatelysocial Social Media Share Buttons & Social Sharing Icons < 2.8.6 - Information Disclosure
Title source: ruleDescription
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.5 via the sfsi_save_export function. This can allow subscribers to export plugin settings that include social media authentication tokens and secrets as well as app passwords.
Exploits (1)
References (2)
Core 2
Core References
Patch, Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/e9e43c5b-a094-44ab-a8a3-52d437f0e00d?source=cve
Scores
CVSS v3
6.5
EPSS
0.1487
EPSS Percentile
94.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (2)
inisev/Social Media Share Buttons & Social Sharing Icons
< 2.8.5
ultimatelysocial/social_media_share_buttons_\&_social_sharing_icons
< 2.8.6
Published
Oct 20, 2023
Tracked Since
Feb 18, 2026