WordPress versions released before 5.2.4 have a security issue that could allow someone to access data without permission. The problem is that the software doesn’t check if a URL is valid by looking at it as a string of numbers and letters. This could lead to a person being able to access data they should not have access to.