Wordpress vulnerability leads to defacement of hundreds of thousands of sites
blog.sucuri.net
blog.sucuri.net
Even large institutions and websites have been hit: Harvard, MIT, glennbeck.com, and many more.
Make sure to update to 4.7.2 if you are running a Wordpress install of 4.7.0 or 4.7.1. There's a REST vulnerability that allows someone to bypass authorization to update or post.
I don't use Wordpress, but if the answer is yes then it is completely dumb to increase the attack surface like that.
My site was hit, as far as hacks go this one wasn't too bad. They defaced the last post, the solution was to revert to an earlier revision and upgrade WP to version 4.7.2.
If we would have had auto updates enabled then this attack would have been prevented. So the takeway from this is make sure that auto updates are enabled.
If you are doing things in WordPress that break with a security patch, you need to re-examine what it is you're doing.
Fortunately the WP and its community is working hard to fix the problems asap and make new release.
The major problem is that people doesn't update the cms. I really recommend the auto-updated and a good management of all plugins versions. If you are a delveoper and you are taking care of several wp sites, there are many plugin that can help you to manage the WP and plugins versions for a large number of sites.