A follow up post on this exploit. I contacted the security admin support for my provisioner, Media Temple, and according to them they claimed that the perpetrators, once they had access to the zen photo admin, they were able to upload altered themes to their intended target without FTP access or SSH. I'm only going by what they said - perhaps deflecting any blame on their part. However, it does appear that Zenphoto has been compromised on a lot of sites with different provisioners recently, by these same individuals. I just wish I knew their methodology of entry so it can be patched.
Thanks for everyone's help.