thanks for the useful link, it does confirm what I thought. The code in my OP is indeed a JS exploit. The trouble is (and why I posted to WP here) I can’t simply edit the index.php as suggested by that site.
This is because the index.php doesn’t actually reference this code at all, I did a search and nothing IFRAME at all is in there. Apparently this is due to an overcomplication (WP) and instead I must find it in the MySQL files or something. Sound about right?