The attackers can execute arbitrary commands via an eval injection vulnerability in the “ix” parameter to wp-includes/feed.php. Also, there is command execution backdoor vulnerability.
Update the WordPress to the latest available version (at least 2.1.2).