PT-2025-32571 · WordPress · Mattermost Confluence Plugin

Lorenzo Gallegos

·

Published

2025-07-10

·

Updated

2025-08-20

·

CVE-2025-44004

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Mattermost Confluence Plugin versions prior to 1.5.0
Description: The Mattermost Confluence Plugin does not verify user authorization to the Mattermost instance, enabling attackers to create channel subscriptions without proper authorization. This is achieved through an API call to the create channel subscription endpoint.
Recommendations: Update Mattermost Confluence Plugin to version 1.5.0 or later.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2025-09764
CVE-2025-44004
GHSA-6FF3-JGXH-VFFJ
GO-2025-3865
OPENSUSE-SU-2025:15469-1

Affected Products

Mattermost Confluence Plugin