We discovered the possible security flaw is in fantastico – the cpanel plugin that allows a one-click wordpress install. Apparently, if you use the same username/password for wordpress as your ftp access, there is an exploitable opportunity for a hacker.