{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2023-5070/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ultimatelysocial:social_media_share_buttons_\u0026_social_sharing_icons:*:*:*:*:*:wordpress:*:*","cpe:2.3:a:ultimatelysocial:social_media_share_buttons_\\\u0026_social_sharing_icons:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":6.5,"id":"CVE-2023-5070"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Social Media Share Buttons \u0026 Social Sharing Icons (\u003c 2.8.6)"],"_cs_severities":["medium"],"_cs_tags":["wordpress","plugin-vulnerability","information-disclosure","cve-2023-5070"],"_cs_type":"threat","_cs_vendors":["Ultimatelysocial"],"content_html":"\u003cp\u003eThe 'Social Media Share Buttons \u0026amp; Social Sharing Icons' WordPress plugin (versions 2.8.5 and earlier) contains an information exposure vulnerability identified as CVE-2023-5070. The vulnerability stems from insecure handling within the \u003ccode\u003esfsi_save_export\u003c/code\u003e function. An authenticated user, such as a low-privileged subscriber, can invoke this function to trigger a full export of the plugin's configuration settings. This exported data includes highly sensitive information, such as third-party social media authentication tokens, application secrets, and stored service passwords. Because these credentials are often utilized for administrative or automated integration with social platforms, their disclosure poses a significant risk of account compromise or unauthorized third-party access. Defenders should identify any instances of this plugin in their environment and ensure they are updated to version 2.8.6 or later.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthorized users to retrieve sensitive third-party service credentials and API tokens. This could lead to the hijacking of connected social media accounts, unauthorized data access, or the use of leaked credentials to gain persistence or facilitate further attacks within connected ecosystems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate 'Social Media Share Buttons \u0026amp; Social Sharing Icons' to version 2.8.6 or later immediately to patch CVE-2023-5070.\u003c/li\u003e\n\u003cli\u003eAudit logs for unauthorized usage of the \u003ccode\u003esfsi_save_export\u003c/code\u003e function or irregular access to the WordPress admin-ajax interface by low-privileged user accounts.\u003c/li\u003e\n\u003cli\u003eRotate all social media API keys and secrets that were configured within the plugin if the environment was exposed prior to patching.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-05T13:19:19Z","date_published":"2026-09-05T13:19:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2023-5070/","summary":"CVE-2023-5070 is an information exposure vulnerability in the Social Media Share Buttons WordPress plugin allowing authenticated users to export sensitive configuration data, including API keys and authentication tokens.","title":"Information Disclosure in Social Media Share Buttons WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2023-5070/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2023-5070","version":"https://jsonfeed.org/version/1.1"}