The point is that finding a vuln and investigating it to the extent required to prove it works is security researcher behavior. Actually exploiting it and dumping all of a site's user data is malicious. If he had leaked stuff relevant to the capitol riots or something, maybe understandable, though using the vuln to do so would still have been wrong.
It's generally a good idea for leakers to be selective about their releases (Snowden did a better job than Manning in that area IMO). I guess Wikileaks is between a rock and a hard place, because if they started editorializing then that would lead to political bias.
Political bias? Like when Wikileaks supported researching the Pizzagate conspiracy during the 2016 US election and posted links to /r/The_Donald "investigation" threads?