On wordpress.org forums there's a list of people who claim their sites were hacked.
http://wordpress.org/support/topic/396524?replies=1
Add BlueHost to the list of shared hosts. Also, this doesn't seem to be exclusive to wordpress, but sometimes other .php files on the servers.