WordPress websites are frequently targeted by hackers because WordPress is so popular. Hackers use bots to find vulnerable websites and gain access for financial reasons like stealing credit cards or infecting users with viruses. The document recommends using the Google Authenticator plugin to add two-factor authentication for logging into WordPress as a prevention method. It also suggests using an automated password generator and changing your admin name for additional security.