What happened
On 8 September someone uploaded a PHP file through an old upload form plugin and used it to add spam pages and send email from the server.
How they got in
The form plugin was three versions behind. The fixed version had been available for months; automatic updates were off.
What I did
Took the site offline for 40 minutes, copied the evidence, removed 2 injected files and 1 admin user, updated every plugin, cleared the mail queue and turned on upload and brute-force protection.
What you should do
Change the passwords you reuse anywhere else. Ask your team to log in again with the new passwords.
Still a risk
The theme is no longer maintained by its author. It is safe today, but plan a replacement within six months.