This Metasploit module exploits a file upload vulnerability in all versions of the Holding Pattern theme found in the upload_file.php script which contains no session or file validation. It allows unauthenticated users to upload files of any type and subsequently execute PHP scripts in the context of the web server.
ee5df7dbf0ac4eac44f2ff30e728e5eeff13120951dead86a3ad506611178a0b
WordPress Holding Pattern theme version 0.6 suffers from a remote shell upload vulnerability.
4503be5e6f6cad5fb8d27275f1d74553eea67b809e8d1c508e90a7b2d37b7114