The LA Times has confirmed the hacking, and says the issue has been resolved. The Los Angeles Times uses WordPress to manage its events.latimes.com subdomestic.com subdomain. A vulnerability in WordPress security was brought to our attention earlier today. We have completed a security review and addressed the issue, and taken additional measures to ensure the security of our sites are secure. In 2013, video surfaced of an XML eXternal Entity (XXE) processing vulnerability in the plugin, but it isn’t clear if that vulnerability was ever patched.”]

