CVE-2023-5070: Social Media Share Buttons & Social Sharing Icons <= 2.8.5 - Information Exposure
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.5 via the sfsisaveexport function. This can allow subscribers to export plugin settings that include social media authentication tokens and secrets as well as app passwords.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for the Social Media Share Buttons & Social Sharing Icons plugin?
The vulnerability ID is CVE-2023-5070.
What is the severity of CVE-2023-5070?
The severity of CVE-2023-5070 is medium with a CVSS severity score of 6.5.
Which versions of the Social Media Share Buttons & Social Sharing Icons plugin are affected by this vulnerability?
Versions up to, and including, 2.8.5 are affected by this vulnerability.
How can this vulnerability be exploited?
This vulnerability can be exploited by subscribers exporting plugin settings that include social media authentication tokens.
Are there any references for CVE-2023-5070?
Yes, you can find references for CVE-2023-5070 at the following links: [Reference 1](https://plugins.trac.wordpress.org/changeset/2975574/ultimate-social-media-icons/tags/2.8.6/libs/controllers/sfsi_buttons_controller.php?old=2956446&old_path=ultimate-social-media-icons%2Ftags%2F2.8.5%2Flibs%2Fcontrollers%2Fsfsi_buttons_controller.php) and [Reference 2](https://www.wordfence.com/threat-intel/vulnerabilities/id/e9e43c5b-a094-44ab-a8a3-52d437f0e00d?source=cve).