Why uploads PHP is a strong signal
WordPress is supposed to store media there. Executable PHP in that tree is unexpected. The scanner sniffs content and extension; it does not run the bytes. A false positive can be marked; the finding stays in the report.
What happens after the finding
Quarantine is copy-verify-remove. Hardening can stop uploads from serving PHP later. Neither step is implied by the match alone. The FREE HTTP scan cannot see uploads files at all.