<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:ultimatelysocial:social_media_share_buttons_&amp;_social_sharing_icons:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aultimatelysocialsocial_media_share_buttons__social_sharing_iconswordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 05 Sep 2026 13:19:19 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aultimatelysocialsocial_media_share_buttons__social_sharing_iconswordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Information Disclosure in Social Media Share Buttons WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2023-5070/</link><pubDate>Sat, 05 Sep 2026 13:19:19 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2023-5070/</guid><description>CVE-2023-5070 is an information exposure vulnerability in the Social Media Share Buttons WordPress plugin allowing authenticated users to export sensitive configuration data, including API keys and authentication tokens.</description><content:encoded><![CDATA[<p>The 'Social Media Share Buttons &amp; Social Sharing Icons' WordPress plugin (versions 2.8.5 and earlier) contains an information exposure vulnerability identified as CVE-2023-5070. The vulnerability stems from insecure handling within the <code>sfsi_save_export</code> function. An authenticated user, such as a low-privileged subscriber, can invoke this function to trigger a full export of the plugin's configuration settings. This exported data includes highly sensitive information, such as third-party social media authentication tokens, application secrets, and stored service passwords. Because these credentials are often utilized for administrative or automated integration with social platforms, their disclosure poses a significant risk of account compromise or unauthorized third-party access. Defenders should identify any instances of this plugin in their environment and ensure they are updated to version 2.8.6 or later.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthorized users to retrieve sensitive third-party service credentials and API tokens. This could lead to the hijacking of connected social media accounts, unauthorized data access, or the use of leaked credentials to gain persistence or facilitate further attacks within connected ecosystems.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update 'Social Media Share Buttons &amp; Social Sharing Icons' to version 2.8.6 or later immediately to patch CVE-2023-5070.</li>
<li>Audit logs for unauthorized usage of the <code>sfsi_save_export</code> function or irregular access to the WordPress admin-ajax interface by low-privileged user accounts.</li>
<li>Rotate all social media API keys and secrets that were configured within the plugin if the environment was exposed prior to patching.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">threat</category><category>wordpress</category><category>plugin-vulnerability</category><category>information-disclosure</category><category>cve-2023-5070</category></item></channel></rss>