Two critical security vulnerabilities called WP2Shell have been discovered in the WordPress content management system versions 6.9.0 to 6.9.4, and 7.0.0 to 7.0.1. These vulnerabilities allow attackers to take over websites without requiring a user account or special plugins. The combination of both vulnerabilities gives attackers full access to execute malicious code on the server. Security firms have reported attempts to exploit these vulnerabilities, and WordPress has released emergency updates (versions 6.9.5 and 7.0.2) to address the issue. WordPress users are advised to update their sites to the latest version immediately to avoid the risk of attacks by hackers.