https://www.prontoadmin.com
What you're talking about is almost always an outdated version of Wordpress, plugins or a vulnerable theme. Check to see which directory the scripts are being uploaded to. That might give you some idea of the script that's vulnerable.
If you're on shared hosting, I see a lot of people set permissions on directories to 777 which will allow other users to write files to those directories.