WordPress versions between 2.8.0 and 2.8.3 have a major security issue which allows anyone (not just hackers, but literally anyone) to change the admin password on your blog