security issue in wordpress?

You can force all visitors to log in before they are allowed to see the pages. This will not work for attachments.

But … if that already is a problem for your site – why did you install WordPress in a publicly accessible directory? You should plan visibility first, then run the installation.

Consider HTTP Basic authentication if you think your users can handle that.