I would disable that functions,
exec, system, passthru, popen, proc_open, shell_exec, proc_close, curl_exec, curl_multi_exec, parse_ini_file, show_source, ini_alter, ini_restore, dl, opcache_get_status, pcntl_exec,
I would update all plugins, search for rootkits and obfuscated code in files...