was it due to the core or a plugin?
https://www.madirish.net/?article=229
I'm betting most WordPress shared hosting doesn't do that, nor give people the means to set up a web app firewall in front of it. Without these things I'd never want to expose a WordPress install to the internet :)
admin / abcd123!
Here is one just from January of this year,
https://www.debian.org/security/2022/dsa-5039
"Several vulnerabilities were discovered in Wordpress, a web blogging tool. They allowed remote attackers to perform SQL injection, run unchecked SQL queries, bypass hardening, or perform Cross-Site Scripting (XSS) attacks."