Impact
The vulnerability is a stored cross‑site scripting flaw due to improper neutralization of input before rendering it in a webpage. An attacker who can inject content that the plugin stores can later cause a victim’s browser to execute that content when the page is viewed. This weakness is categorized as CWE‑79.
Affected Systems
The vulnerability exists in all published releases of the WordPress plugin Proxy & VPN Blocker up to and including version 3.5.8. The description specifies that the affected range is from n/a through ≤ 3.5.8, meaning earlier unversioned releases and all versions up to the vulnerable boundary are impacted.
Risk and Exploitability
The CVSS score is 7.1, indicating high severity. The EPSS score of less than 1 % suggests that exploitation is currently unlikely but possible. The issue is not listed in CISA’s KEV catalog. Based on the description, the flaw allows the injection of malicious payloads that are stored and later rendered to site visitors. The stored nature of the flaw means that a single successful injection can persist until the vulnerability is patched or mitigated.
OpenCVE Enrichment