Same attack vector was used on me a few years ago (old Wordpress installs floating around in "dev" folders). I set all hosted WP installs on my server to automatically update to try and prevent that kind of attack again, and I always uninstall every plugin and theme that isn't being used.
It was brutal - pretty much every .htaccess file and *.php file was infected and had to be manually cleansed due to a bad backup. Took an entire weekend, morning to night, to fix.
I appreciate Wordpress' accessibility and everything, and I've built a lot of sites on top of it, but holy crap is it a mess internally.