Sorry if this has already been asked, but i didn't find it. I noticed that if i save a draft, it's visible through domain.com/p=## or whatever. Isn't this a problem? Anyone can just sequentially change numbers after p= and view all your drafts etc. Shouldn't wordpress return an error or something if someone puts in a url with a postid that is marked as draft?
sure they'd have to have some alternate way for the author to preview, but still...