Vivek Bansal hacked Facebook Security and brought it to their notice 11 months ago. He received $2000 from Facebook as a token of their appreciation, as well as an email stating that they had patched the vulnerability. However, he was able to reproduce his exploit and breach their security AGAIN using the same script. He was shocked that everything went off as it had before, so I wrote them again expressing my concerns. With hundreds of millions of people accessing Facebook every day, the fact that Facebook wont patch security vulnerabilities is very serious.”]
Source: https://informationsecuritybuzz.com/news/facebook-security-loophole-reported-year-ago-still-open/