Attackers have been carrying out WPSetup attacks, taking advantage of users who have installed WordPress but not yet configured it. Attackers mount thousands of scans each day for /WP-admin/setup-config.php, a URL that new WordPress installations use to setup new sites. With admin access, an attacker can enter their own database name, username, password, and even database server. The biggest increase in scans roughly 7,500 a day came on May 30.
Source: https://threatpost.com/attackers-using-automated-scans-to-takeover-wordpress-installs/126815/