It's important to recognize that this is not an exploit or high-tech exfiltration: it's extremely well-documented in https://developers.facebook.com/docs/reference/javascript/FB... and https://developers.facebook.com/docs/javascript/reference/FB... - the Facebook library even assumes that potentially multiple scripts may be checking repeatedly, and caches accordingly. Facebook is incentivized to make it as easy as possible to integrate their login across the internet, and that entails removing any requirements such as server-side processing that would discourage every tag from including this code.
Seeing this and being surprised is like watching a teen movie where the gossiper invites the entire school to listen in on the phone line while the protagonist is (unwisely) sharing a secret with them, and thinking as you watch, "that's totally out of character for the gossiper - even though they want to collect people's information themselves, there's no way they would invite other people to listen in as they're in the process of receiving that information."