PT-2025-32571 · WordPress · Mattermost Confluence Plugin

·

CVE-2025-44004

·

Published

2025-07-10

·

Updated

2025-08-20

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Mattermost Confluence Plugin versions prior to 1.5.0
Description: The Mattermost Confluence Plugin does not verify user authorization to the Mattermost instance, enabling attackers to create channel subscriptions without proper authorization. This is achieved through an API call to the create channel subscription endpoint.
Recommendations: Update Mattermost Confluence Plugin to version 1.5.0 or later.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09764
CVE-2025-44004
GHSA-6FF3-JGXH-VFFJ
GO-2025-3865
OPENSUSE-SU-2025:15469-1

Affected Products

Mattermost Confluence Plugin