CVE-2023-5070
Social Media Share Buttons & Social Sharing Icons <= 2.8.5 - Information Exposure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.5 via the sfsi_save_export function. This can allow subscribers to export plugin settings that include social media authentication tokens and secrets as well as app passwords.
El complemento Social Media Share Buttons & Social Sharing Icons para WordPress es vulnerable a la exposición de información confidencial en versiones hasta la 2.8.5 incluida a través de la función sfsi_save_export. Esto puede permitir a los suscriptores exportar configuraciones de complementos que incluyen tokens y secretos de autenticación de redes sociales, así como contraseñas de aplicaciones.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-09-19 CVE Reserved
- 2023-10-16 CVE Published
- 2023-10-17 First Exploit
- 2024-08-02 CVE Updated
- 2024-10-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/RandomRobbieBF/CVE-2023-5070 | 2023-10-17 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ultimatelysocial Search vendor "Ultimatelysocial" | Social Media Share Buttons \& Social Sharing Icons Search vendor "Ultimatelysocial" for product "Social Media Share Buttons \& Social Sharing Icons" | < 2.8.6 Search vendor "Ultimatelysocial" for product "Social Media Share Buttons \& Social Sharing Icons" and version " < 2.8.6" | wordpress |
Affected
|