1. Administrator password compromised.
Be sure to set only one admin account and others to Editor. Change passwords as well.
2. Exploitable plugins.
Be sure to delete all not required and inactive plugins. Update all to the latest version, and be careful in noting any premium type plugins and checking to see if you have the latest version of those as well.
3. Exploitable themes.
Be sure to delete all not required themes, so as not to leave any hidey holes for hackers to hide their stuff.
4. Check your hosting account and be sure to delete all extra FTP accounts. Change your main hosting account password and primary FTP account as well.
These are the basics. Otherwise, try any of the numerous security plugins available in the repository to see if they find anything suspicious.
Best Wishes in your quest to secure your website!
]]>