Attackers are using automated scans to target freshly installed WordPress websites. Attackers aim to find new WordPress installs that are not yet configured by the administrators. The WPSetup attack leverages on the fact that a user hasnt finished setting up its WordPress installation, the attacker can exploit this condition to complete the users installation. The attackers can take over the website running their own installation or creating a supplementary account. WordFence recommends users to create a specially coded.htaccess file in the base of their web directory.”]
Source: https://securityaffairs.co/wordpress/60981/hacking/wordpress-wpsetup-attack.html