PHP file dropped into Forminator uploads directory via web server process

Detects the creation of .php files within the wp-content/uploads directory tree by common web server or PHP-FPM processes. This behavior is indicative of an adversary attempting to drop a web shell via file upload bypass vulnerabilities, such as those exploiting MIME-type manipulation.