Attackers have begun widely exploiting two critical vulnerabilities in WordPress that, when chained, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.