Disguised Backdoor Plugin Upload in WordPress

Detects the uploading of a plugin matching known disguised slugs ('content-delivery-helper' or 'database-optimizer') used by attackers to install backdoors after establishing a rogue admin account in WordPress environments. This rule specifically targets POST requests to the WordPress plugin update endpoint with these malicious plugin names in the query string.