After a bit more time investigating this issue, we were able to confirm that the attack vector is the RevSlider plugin.
All our clients who have a WordPress site management contract with us have already been updated to the latest version.
All other clients are asked to update their Revolution Slider plugin to version 4.2 or greater, which resolves the issue, as soon possible. Not doing so will risk your site being hacked.
We use cookies to provide our services and for analytics and marketing. To find out more about our use of cookies,
please see our Privacy Policy. By continuing to browse our website, you agree
to our use of cookies.