A site cleaned but not hardened is usually compromised again within days. There are four usual reasons.
THE BACKDOOR WAS MISSED
Attackers plant several. Removing the visible defacement while leaving a small obfuscated file elsewhere means they simply walk back in. Backdoors are often placed in folders unrelated to the original entry point, sometimes inside an unused theme.
THE VULNERABILITY WAS NOT PATCHED
If an out-of-date plugin allowed the first compromise and it is still out of date, the same automated scanner will find it again. Cleaning files does not patch software.
CREDENTIALS WERE NOT CHANGED
If the attacker obtained your FTP or admin password, they no longer need the vulnerability. Change every password, not just the one you think was used.
THE SOURCE IS YOUR OWN COMPUTER
Malware on your laptop that steals saved FTP passwords will hand over the new credentials as soon as you set them. If a site is repeatedly defaced with no server-side explanation, scan your own machine.
DOING IT PROPERLY
Clean thoroughly, patch everything, rotate all credentials, harden, then monitor for a few weeks. Skipping any one of these stages usually means doing the whole job again.