Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file.
https://themify.me/blog/urgent-vulnerability-found-in-themify-framework-please-read
https://themify.me/blog/updated-themify-framework-to-fix-the-vulnerability