My wordpress header.php got hacked
arlocarreon.com
arlocarreon.com
In my case, the attack was from "/blog/wp-content/themes/default/functions.php", which isn't even a theme in recent WordPress builds; it's simply been left over from the many upgrades over the years.
The other most common route for such injection is not always WordPress itself, but instead through insecure, third-party themes, since theme designers are not always programmers.