The sooner you update your site the better, as the security fixes to deal with WordPress vulnerabilities that existed in the previous versions are also rolled out with those updates.
A word of caution, make sure to access your FTP client and click on any WordPress file/folder and then click on "File Permissions" to check if it is set to “777”. If not, you would lucky if your website haven't been hacked, or else change the CHMOD value to 744.