I believe this was to mitigate certain PHP code execution and file upload exploits. It used to be fairly commonplace that file upload code was buggy, allowing you to upload arbitrary files into the web root. So people would upload “PHP shells”, which are backdoor scripts, somewhere on the web root and then navigate to that URL to execute the shell.
I think this technique still remains common to escalate getting admin on a WordPress blog to taking over the host.