WordPress before 5.2.4 contains an information disclosure caused by mishandling of the static query property, letting unauthenticated users view certain content, exploit requires no authentication.
id: CVE-2019-17671
info:
name: WordPress <= 5.2.4 - Unauthenticated View Private/Draft Posts
au
...