i assume your friends was using WP V 3.0.1 as that version has some vulnerabilities , which can be exploited by malicious people to conduct reflected cross-site scripting "XSS" attacks, just make sure to upgrade it to 3.0.3 or upper
Source: Me (Ex Blackhat H4Cker ; )