I found and removed a bunch of files and plugins which were clearly meant to give the hacker backdoor access to upload any files into my WordPress setup, though I still don't know how in the first place.