It doesn't have to be a "hacker".
If you allow members to upload "stuff" to your site, you have the potential for a huge security hole.
If you have that feature on your site, make very sure that people cannot upload arbitrary files. If that is the source of the compromise, then merely...