There is always a risk your site might be hacked, but that risk is present for both open source and in-house software.
For Wordpress in particular, it is best to make sure your installation is up-to-date with the latest release each time they provide an update. In fact, Google itself will provide a message in your Google Webmaster Tools if it notices your site is behind on releases.
Are your designers/host in-house? If the risk is too great for them, perhaps they can serve your blog content from a different server.
If your designers/host are not in-house, they may be telling you this because of their own limitations whatever they may be.
My suggestion would be to ask for more information. Why is the risk high for your website? Can the blog content be hosted on a separate server to alleviate the concern?