Wordpress Alert: PHP execution inside upload directories

The web server executes scripts stored in uploads. An upload flaw can become server code execution.

What it looks like

The web server executes scripts stored in uploads.

Why it matters

An upload flaw can become server code execution.

What to check

Check server rules so uploads are served as data, not executable code.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP file upload guidance, WordPress hardening guide.