Praefectus wrote:
Were you using the timthumb plugin?
No I was not, but after checking my access logs I noticed some files with that name were uploaded, also I believe the theme I have used an older version of it. I updated it.
I've gone ahead and lower a few permissions, changed all of my system passwords, change my db prefix, installed a few system scanner plugins and got rid of all the infected files, would there be anything else I could do to patch a security exploit?
Update: Researched the timthumb plugin, and found out about the exploit. I've updated it, I guess that's how they did it.