CVE-2023-5070

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
20/10/2023
Last modified:
08/04/2026

Description

The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.5 via the sfsi_save_export function. This can allow subscribers to export plugin settings that include social media authentication tokens and secrets as well as app passwords.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ultimatelysocial:social_media_share_buttons_\&_social_sharing_icons:*:*:*:*:*:wordpress:*:* 2.8.6 (excluding)