You have probably been hacked. Check by entering your site at https://sitecheck.sucuri.net.
If hacked, get a fresh cup of coffee, take a deep breath and carefully follow this guide. When you’re done, you may want to implement some (if not all) of the recommended security measures.
If you’re unable to clean your site(s) successfully, there are reputable organizations that can clean your sites for you. Sucuri and Wordfence are a couple.
@sterndata I just entered my site into that link and it said no malware found, so does that mean I can rule out being hacked? (Thanks for your response)
no, not necessarily. Install the plugin “wordfence” and use it to scan your site.
@sterndata It found some legacy CSS files but it seems they’re just leftover files which are apparently nothing to be alarmed about, right?
probably, but if this issue is still occurring, you need to treat your site as if it were hacked.
I just wanted to provide an update on this issue as I’ve since found what has caused it. Anrdoezrs is a redirect domain used by Commission Junction who I signed up to a long time ago and had to implement code in the Head of the site to activate but I’ve never used. I recently found it in the header site file, looked up the whois record for anrdoezrs, found Conversant Media which is the company of CJ and then realised that’s what had happened. Basically me being stupid/forgetful but I wanted to add this update as I have seen other unanswered questions with the same issue so hopefully this helps others.