When WordPress implemented the new Trash feature they failed to change the permissions granted when the post is in the trash. This means that an unauthenticated user cannot see the post, however an authenticated user can, no matter what privileges they have, even ‘subscriber’. See ExploitDB for PoC
2014-08-01 (about 8 years ago)
2014-08-01 (about 8 years ago)
2020-10-31 (about 2 years ago)