VYPR
Medium severity5.9NVD Advisory· Published Mar 6, 2026· Updated Apr 22, 2026

CVE-2024-35644

CVE-2024-35644

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pascal Birchler Preferred Languages allows DOM-Based XSS.This issue affects Preferred Languages: from n/a through 2.2.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

DOM-Based XSS in WordPress Preferred Languages plugin (≤2.2.2) allows attackers to inject malicious scripts via improper input neutralization.

Vulnerability

Overview

The Preferred Languages plugin for WordPress versions 2.2.2 and earlier contains a DOM-Based Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user input during web page generation [1]. This flaw allows an attacker to inject arbitrary JavaScript into the DOM of a victim's browser when they interact with a crafted page or link.

Exploitation

Details

Exploitation requires user interaction, such as clicking a malicious link or visiting a specially crafted page [1]. The attack can be initiated by a privileged user role, but successful execution depends on the victim performing an action. The vulnerability is DOM-based, meaning the payload is processed client-side rather than stored on the server.

Impact

Successful exploitation could allow an attacker to inject malicious scripts, including redirects, advertisements, or other HTML payloads, which execute when visitors access the affected site [1]. This can lead to defacement, phishing, or further compromise of user sessions.

Mitigation

The vendor has released version 2.3.0 which resolves the vulnerability [1]. Users are strongly advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. If unable to update, consult your hosting provider or web developer for assistance [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

1