Two days ago, Rank Math closed about a dozen security issues in 1.0.277. This plugin runs on over 4 million sites.
In that same update, group[.]one (who also owns WP Rocket) now gets administrative privileges to your site.
Last time, I classified something like this as a
Fix this one next: wp_crop_image() takes any post ID, reads _wp_attached_file, and sends that path to the image editor. It never checks that the ID is an image. I reported that in 2022 (HackerOne 1593366, with a PoC).
It is still sitting there in 7.0.4.
You just taught Imagick