There are bots who mindlessly throwing HTTP requests on some known vulnerabilities, they don't really check whether you're running wordpress or not. Every web server bombarded by those requests, that's not something you should be worried about.
I am worried because I don't know. I covered some basics like SSL, XSS (htmlescape), sessions are redirect related, PDO/sql... no ddos/load balance... backup backup
it is crazy to just randomly try different octet combinations to form a new ip and see what you get... what about ipv6 hoho
thanks
I'm not sure if it's possible to "bounce off" an attack from someone else's ip, by "attack" I mean a specific requested URL that is looking for an exploit.
This may also be a good read: