CVE-2024-35644
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pascal Birchler Preferred Languages allows DOM-Based XSS.This issue affects Preferred Languages: from n/a through 2.2.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
DOM-Based XSS in WordPress Preferred Languages plugin (≤2.2.2) allows attackers to inject malicious scripts via improper input neutralization.
Vulnerability
Overview
The Preferred Languages plugin for WordPress versions 2.2.2 and earlier contains a DOM-Based Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user input during web page generation [1]. This flaw allows an attacker to inject arbitrary JavaScript into the DOM of a victim's browser when they interact with a crafted page or link.
Exploitation
Details
Exploitation requires user interaction, such as clicking a malicious link or visiting a specially crafted page [1]. The attack can be initiated by a privileged user role, but successful execution depends on the victim performing an action. The vulnerability is DOM-based, meaning the payload is processed client-side rather than stored on the server.
Impact
Successful exploitation could allow an attacker to inject malicious scripts, including redirects, advertisements, or other HTML payloads, which execute when visitors access the affected site [1]. This can lead to defacement, phishing, or further compromise of user sessions.
Mitigation
The vendor has released version 2.3.0 which resolves the vulnerability [1]. Users are strongly advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. If unable to update, consult your hosting provider or web developer for assistance [1].
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=2.2.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
1- Thieves unlock stolen iPhones using cheap tools sold on TelegramHelp Net Security · May 15, 2026