A cross-site scripting vulnerability in WordPress plugin WP Statistics could have enabled full website takeover.
Source: Threadpost