Wordpress is a very popular target for hackers. They normally get in with holes found in plugins, themes or in wordpress core.
An up-to-date installation (including plugins and themes) is crutial!
Hardening Wordpress is sadly not a part of the standard installation documentation, but they have a guide available in the "codex": http://codex.wordpress.org/Hardening_WordPress
Removing unused plugins and users, setting htpasswd and/or ip-whitelisting in //wp-admin// also should be considered.