Check the plugins for any newly added ones, there could be code present in one of the plugins allowing some form of shell script access, or loading a file that allows such access.
You can use Securi to check the site, it does check forums a little better than other scanners:
https://sitecheck.sucuri.net/results...ars.com/forum/
Be sure to also run suspect file versions from the back-end under:
> Maintenance > Diagnostics > Suspect File Versions
You can go further and read the following guides as well to run other checks:
https://forum.vbulletin.com/blogs/mi...vbulletin-site
https://forum.vbulletin.com/blogs/za...ve-been-hacked