Preferred Languages

Preferred Languages has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Preferred Languages has a vendor fix available, so running the current release closes it.

All of these findings were reported by Jayden Caelli. Preferred Languages is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
4.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Preferred Languages vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.4CVE-2024-35644

Preferred Languages <= 2.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv2.4.2

Preferred Languages

Pascal Birchler

Author

Pascal Birchler

5.0(18)
100/100
Last Updated
2026-08-18 (26d ago)
Active Installs
3,000+
Downloads
114,929
Requires WP
6.6+
Requires PHP
7.2.24+
Tested up to
WP 7.1
Created
2017-10-02 (9y ago)

Thanks to language packs it’s easier than ever before to change the main language of your site. However, in some cases a single locale is not enough. When WordPress can’t find a translation for the active locale, it falls back to the original English strings. That’s a poor user experience for many non-English speakers. This feature project aims to change that by letting users choose multiple languages for displaying WordPress in. That way you can set some sort of “fallback chain” where WordPress tries to load translations in your preferred order. Please help us test this plugin and let us know if something is not working as you think it should. Keyboard Shortcuts Arrow Up: Move selected locale one position up. Arrow Down: Move selected locale one position down. Home: Select first locale in the list. End: Select last locale in the list. Backspace/Delete: remove the selected locale from the list. Alt+A: Add the current locale from the dropdown to the list. Note: the Preferred Languages UI needs to be focused in order for the keyboard shortcuts to work. Merging Translations Previously, only the first available translation for a given locale and domain will be loaded. However, when translations are incomplete, some strings might still be displayed in English. That’s a poor user experience as well. To prevent this, Preferred Languages now automatically merges all incomplete translations in the list. the preferred_languages_merge_translations filter can be used to opt out of this behavior. It provides three parameters: $merge – Whether translations should be merged. Defaults to true. $domain – The text domain $current_locale – The current locale. Get Involved Active development is taking place on GitHub. If you want to get involved, check out open issues and join the #core-i18n channel on Slack. If you don’t have a Slack account yet, you can sign up at make.wordpress.org/chat/.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C