If you can, I’d start by running a diff of your site’s current code against a latest ‘clean’ backup or against the clean WordPress codebase of the same version. If there’s nothing in WordPress core then you need to check the active theme and possibly even plugins. Easiest to narrow it down is just disable all plugins and check if issue persists, then switch to a clean version of some default theme like twentysixteen, then check again.
]]>Anything less will probably result in the hacker walking straight back into your site again.
Additional Resources:
Hardening WordPress
https://sitecheck.sucuri.net/scanner/
https://www.unmaskparasites.com/