Executive brief
The Proxy & VPN Blocker plugin for WordPress, which is used to prevent visitors from using anonymizing services to access a website, contains a security flaw. This vulnerability allows an attacker to inject malicious scripts into the website that will execute in the browser of other users, such as administrators or visitors. If exploited, this could lead to unauthorized actions being performed on behalf of users, theft of session information, or redirection to malicious websites.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Proxy & VPN Blocker plugin for WordPress (versions <= 3.5.8). The flaw stems from improper neutralization of user-supplied input during web page generation, allowing an unauthenticated attacker to inject arbitrary JavaScript or HTML payloads. Because the vulnerability is 'Stored', the malicious script is saved on the server and executed in the context of a victim's browser when they visit an affected page. Exploitation requires minimal user interaction (such as a privileged user viewing a specific administrative page or log) and can lead to session hijacking or unauthorized configuration changes. The issue is resolved in version 3.5.9.
Affected products
- Proxy & VPN Blocker Proxy & VPN Blocker <= 3.5.8
Timeline
- 2026-04-28: disclosed: Reported by Peng Zhou
- 2026-07-08: advisory: Patchstack published advisory
- 2026-07-13: advisory: NVD published CVE record
- patched: Fixed in version 3.5.9