Simply create a .htaccess file and upload it to your site's /wp-includes/ and /wp-content/uploads/ folders.

You can create an .htaccess file using Notepad (TextEdit on Mac). All you need to do is paste the below code in your .htaccess file.

deny from all

After creating your .htaccess file, upload it to the /wp-includes/ and /wp-content/uploads/ folders. You can upload it through FTP client or File Manager (cPanel dashboard).

After uploading the .htaccess file with this code, it will disable PHP execution from these directories.
