DDoS attacks are a growing phenomenon that governments and businesses are facing. In a recent attack, thousands of legitimate WordPress were compromised by hackers without putting them at risk. Instead, the attackers exploited the WordPress “Pingback Denial of Service possibility” vulnerability (CVE-2013-0235).
According to security firm Sucuri, a recent attack leveraged over 162,000 legitimate WordPress websites to carry out a large-scale distributed denial-of-service (DDoS) attack.
The attack exploited an issue in WordPress ' XML-RPC (XML Remote Procedure Call) , which is used to provide services like Pingbacks, trackbacks, and allows anyone to initiate a request from WordPress to an arbitrary website.
More information can be found here.

