Themes and Security
It’s very simple - don’t just upload a new theme without having a look at its code first… You are laying open your server to the complete whim of the theme programmer.
Examples of the problem here and here are only the tip of the iceberg in terms of what could be achieved as exploit.

