Two serious vulnerabilities have been discovered in the WordPress content management system that hackers could exploit to take control of websites. These security flaws, named WP2Shell, affect WordPress versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. The attacks are dangerous because they do not require any special plugins or user accounts, allowing anyone to exploit the vulnerabilities. The combination of both flaws allows hackers to execute malicious code on the server and take over affected WordPress websites. Cybersecurity firms have reported attempts to exploit these vulnerabilities and emphasized their wide-ranging potential impact given the popularity of the WordPress platform.