The Feed Them Social plugin for WordPress has a security vulnerability in versions 2.9.8.5 and earlier. Attackers that are not logged in can exploit this vulnerability by taking advantage of a lack of or incorrect nonce validation on the fts_refresh_token_ajax function. This would allow them to change the plugin settings without permission.