By default, the WordPress admin dashboard allows administrators to modify PHP files of plugins and themes.
If a website is lacking in proper security, attackers may take advantage of this WordPress PHP Editing functionality. Therefore, it is highly recommended that PHP Editing on Plugins and Themes is disabled.
It can be disabled easily by adding the following line to the wp-config.php file of your website:
define('DISALLOW_FILE_EDIT', true);
Here is a screenshot of where exactly you need to place the code within the wp-config.php file:

The wp-config.php file is located in the public_html/ directory of the website and can be edited via FTP.
To learn how to use FTP with FileZilla in order to connect to your account here, you can follow this step by step article with screenshots:
https://wpxhosting.com/knowledgebase/article/63/how-to-use-filezilla-for-ftp-sftp-with-your-wpx-hosting-account-/
If you run into trouble and get stuck, please raise a support ticket here:
https://wpxhosting.com/tickets/new/
and we will reply ASAP.