A security researcher accidentally discovered a method by which hackers run campaigns on Facebook's platform, and reported it to the company's bug bounty program. Facebook ignored the researcher's report, and has not taken any action to limit it, as the specific method does not change the status of users' accounts in any way.
The POC (proof of concept) code has been published showing how easy it is for a developer to share a link multiple times.
The security researcher began analyzing the campaign when he noticed that many of his Facebook friends were sharing a particular link with funny images. When he opened that link, before he could even see the funny images, he was asked to confirm that he was over 16 years old.
"After someone confirms that they are over 16 years old, you are taken to the page with the funny images. What they don't know, however, is that they automatically share the link from their account.".

What he discovered with a quick look at the page's code is a suspicious iframe tag, which contains a URL responsible for the automatic sharing. This particular method targets Facebook mobile users and only works if the selected language is French.
This particular method is called click jacking. It works by loading an iframe that is in a hidden layer in front of the page we want to view.
Facebook quickly responded to the report, and stated that it would not make any changes, as this method does not alter the user's account in any way, so there is no security issue.
