PT-2025-32578 · WordPress · Mattermost Confluence Plugin

Lorenzo Gallegos

·

Published

2025-08-11

·

Updated

2025-08-20

·

CVE-2025-53857

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Mattermost Confluence Plugin versions prior to 1.5.0
Description: The Mattermost Confluence Plugin does not verify user access to channels, potentially allowing unauthorized access to channel subscription details. This occurs through an API call to the GET /autocomplete/GetChannelSubscriptions endpoint.
Recommendations: Update Mattermost Confluence Plugin to version 1.5.0 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-53857
GHSA-42M6-5VM7-FJV2
GO-2025-3864
OPENSUSE-SU-2025:15469-1

Affected Products

Mattermost Confluence Plugin