You should definitely use WPA-PSK as it is more secure than WEP, and all standard equipment now supports it. However, for as much as WEP is put down for being "insecure" - it is not a trivial task for someone to crack it, and I doubt someone would really invest the effort just to get into your home network (if you had a corporate network, that might attract more attention).
I set about trying to crack my own home WEP network just to see how hard it would be. First you need to get the right software, most of which runs on Linux (this is going to be beyond most average users). Eventually I found a copy for Windows (that only runs from the command line) but found that it didn't support my wireless card's chipset. So I borrowed a compatible card and after some tweaking, it started capturing packets. But for an infrequently used home network, there was not nearly enough traffic to get enough packets to crack the password. The solution is to use packet injection (where you create your own traffic on the target network, then use those packets to decrypt the key). However, this requires a second computer with a wireless card. Once I got that setup, it was still fairly slow to generate sample packets. At the rate I was going, it would have taken several days or possibly even a few weeks to get enough data to crack the password. I also found that the cracking software was quite unreliable and would often crash randomly, losing a entire days' worth of packets. At that point, I gave up, never successfully breaking into my own network.
Now, if you were experienced with this, and had done all the prep work (bug-free software/hardware, probably running linux, and a 2nd computer for packet injection) then it would go a lot faster, but you'd still have to wait for the software to capture enough packets to get a password. And I seriously doubt that anyone with this capability is going to bother breaking into my home network...there's just nothing exciting about that. Even if he did this in the hopes of getting into my Vanguard account, there's another layer of security from the browser encryption. Could someone potentially bypass that with man-in-the-middle attack and then get my Vanguard info? Theoretically, yes, but they would have to know that I have an account there...and do a whole lot more legwork after cracking WEP.
In terms of the effort vs. return tradeoff...you could do all of this work in the off chance of catching someone with a large account, and then hope they don't notice when you transfer all your funds out. But it's far easier to send out phishing emails or distribute spyware, so these types of attacks are much more prevalent and present a much greater risk to the "average" person.