PHP file written to Elementor Pro forms uploads directory (CVE-2026-32475)
Detects the creation of PHP files within the 'wp-content/uploads/elementor/forms/' directory of a WordPress installation. This behavior is highly suspicious as it often indicates an attempt by an attacker to deploy a web shell or other malicious script following successful exploitation of the Elementor plugin, which allows for arbitrary file uploads.
Microsoft Sentinel (KQL)

