
If a scanner sent you here citing CVE-2017-5487: that was fixed in WordPress 4.7.1, in January 2017. 4.7.0 returned authors of any public post type. 4.7.1 narrowed it to post types that opt into REST. What you are seeing on 7.0 today is the intended behavior, not the old flaw.
Post summary
The post clarifies that CVE‑2017‑5487 was fixed in WordPress 4.7.1 and that the behavior observed on version 7.0 is intended, debunking concerns about an active flaw.

