A number of months ago a DDoS attack against a website used a functionality in all WordPress sites since 2005 as an amplification vector. According to one report more than 162,000 WordPress Sites sent requests to the target.
more here......http://h30499.www3.hp.com/t5/Fortify-Application-Security/Security-issues-in-WordPress-XML-RPC-DDoS-Explained/ba-p/6601700#.VAloLPldWSo
more here......http://h30499.www3.hp.com/t5/Fortify-Application-Security/Security-issues-in-WordPress-XML-RPC-DDoS-Explained/ba-p/6601700#.VAloLPldWSo