Did your WordPress site get hacked? is a great post by Donncha examining the latest “popular” hack(s), how to prevent them and/or how to recover.
I’ll summarize: Don’t be slow to upgrade.
Lots of activity these days on the WordPress Support forums related to folks getting hacked. Hopefully Donncha is correct in stating that there’s nothing new under the sun, just the same old hacks going around.
If you suspect you’ve been compromised, you’ll want to start with this article. And hey, don’t forget the new password security feature in 2.5x.
Possibly Related posts:




Yes, mine did. I guess you already knew this, but I can verify that updating WordPress IS WITHOUT A DOUBT very important. My site was de-indexed by Google because of foul-play.
I did a recent blog post about the hackery, and within the same day Google re-indexed me. Coincidence?
the post ==> http://www.redesign.creativecomponent.com/is-there-life-after-google/