Do you have phpmyadmin installed? If you do, and someone guesses what directory you installed phpmyadmin to, they can get into your database, which could give someone full control of your WordPress.
Alternatively, if your password was easily guessable they might have gotten in that way.
Alternatively, check that you’re the only user on the server who has access to that database.