There exists many exploitation mechanisms. First, I'll talk about editing the PHP code in the theme.
Scenario: I was able to find credentials=> Elliot:ER28-0652
I logged in to the admin panel and found out the code for the theme was editable
I simply edit this file and add my own reverse shell code here