We were told that third parties can't get any information from the social plugins. The data is served directly from Facebook using an iframe.
Facebook uses their parent-child-parent iframe tricks to assign a first-party cookie for the host domain. This cookie contains the Facebook user id and the OAuth access token used to make requests to the Graph API.
Any javascript running on the page can snatch that cookie and send the data back up to its mothership, which can then impersonate the host domain to make API requests on behalf of the user. Fun stuff.