-
AuthorPosts
-
April 11, 2025 at 11:47 am #233312
Vo NamParticipantHi team,
I’m using the WooCommerce Product Size Chart plugin on my WordPress site, and I’ve noticed an issue that could be either a file corruption or a potential vulnerability.
When accessing the following file directly:
css
/wp-content/plugins/woocommerce-product-size-chart/assets/img/svg/ruler-icon-3.svg
The browser returns the following error:This page contains the following errors:
error on line 2 at column 1: Extra content at the end of the documentThis error suggests that the SVG file might be malformed (e.g., invalid XML structure), or it may have been modified unexpectedly.
Additionally, I’ve observed suspicious automated requests targeting this file (and others in the plugin) in my server logs — including user-agents like masscan, or requests that resemble vulnerability scanning tools. This raises concern about the possibility of bots trying to exploit known SVG or plugin-related vulnerabilities.
What I’d like to clarify:
Is this SVG file (ruler-icon-3.svg) supposed to be accessed publicly?Has there been any report of XSS or injection risks involving SVGs in your plugin?
Could you please provide a clean version of the file, or advise if it’s safe to restrict access?
Thank you for your time and support!
Kind regards,
If possible, please reply in Vietnamese.Attachments:
You must be logged in to view attached files. -
AuthorPosts
You must be logged in to see replies to this topic. Click here to login or register