WordPress should never execute PHP files inside wp-content/uploads. That folder holds images, PDFs, and other media, never code, so blocking PHP execution there closes off a common attack path without touching how your site works day to day.
Why this matters
File upload forms are a favorite target. If an attacker finds a way to drop a PHP file into your uploads folder, whether through a vulnerable plugin, a compromised admin account, or a sloppy import tool, and that folder allows PHP execution, the attacker's script runs. That's how a single bad upload turns into a full site compromise: backdoors, spam injection, malware distribution, the works.
Blocking execution doesn't stop the bad file from being uploaded. It stops the server from running it as code. The file just sits there as inert data, harmless.
Check whether you're already covered
Flashcloud hosting runs Imunify360 as a web application firewall at the server level, so many attempts are already blocked before they reach your files. Adding the rule below closes the gap further.
Option 1: a WordPress security plugin
One option for most site owners is a security plugin that includes this as a built-in hardening option. Open wp-admin → Plugins and check whether your existing security plugin (Wordfence, iThemes Security, or similar) has a "disable PHP execution in uploads" or "prevent PHP execution in upload directories" toggle under its hardening or firewall settings. If it does, flip it on and you're done. No file editing required.
If you're not running a security plugin and don't want to add one just for this, use Option 2 instead.
Option 2: add an .htaccess rule
Flashcloud's hosting uses LiteSpeed Web Server, which reads standard .htaccess directives for Apache compatibility. Add an .htaccess file inside the uploads folder to block PHP execution there.
- Open File Manager from your portal service page, or connect with an FTP client.
- Navigate to
wp-content/uploads. - Create a new file named
.htaccessin that folder if one doesn't already exist there. - Add these lines:
<FilesMatch "\.(?i:php)$">
Require all denied
</FilesMatch>
Save the file. Any request for a .php file inside uploads now returns a 403 error instead of executing. Test it by uploading a harmless test PHP file (a single line like <?php echo "test"; ?>) and requesting its URL directly in a browser. You should get a 403, not the "test" output.
This rule only affects the uploads folder. It won't touch your theme or plugin files elsewhere in the install, so normal WordPress operation is unaffected.
Test on staging first if you're unsure
Some page builders and gallery plugins generate helper files inside uploads subfolders that could, in rare cases, need to execute. This is uncommon, but if your site relies on unusual upload-processing plugins, apply the rule on a staging copy first and click through your media-heavy pages before pushing it live. See Using WordPress staging for the workflow. On a store, test uploads used for product images too. See Running a WooCommerce store for more on keeping a store site stable through changes.
When to contact support
If you find PHP files in your uploads folder that you didn't put there, that's an active compromise, not routine maintenance. Open a ticket from Support → New ticket in the portal. Real humans handle these and can walk you through next steps.