Are you using the Yellow Pencil Visual Theme Customizer? (It’s used by over 30,000 websites)
If so you should update it immediately!
According to Bleeping Computer and WordFence there is a privilege escalation bug that allows hackers to take over your site.
It has been removed from the WordPress respository.
You should receive a notification in your Plugins to update this, if not then you can download the update from HERE.