You can try this:
I was able to add a LAN-to-any-zone Traffic Rule to block the NordVPN app on a client device from connecting over TCP, UDP and NordLynx (WireGuard), with WireGuard still running on my GL-MV1000W Brume-W router. However, it seems that the NordVPN app may use alternate ports that have to be blocked also, not only the standard VPN ports.
I do not work for and I am not directly associated with GL.iNet