Found this on a WordPress server under the filename wp-includes/class-wp-image-editor-fd.php
when WordFence picked it up as being an unexpected file.
Link to source is here: https://pastebin.com/DWe4d33K
Very clearly looks like malware due to the classic obfuscation. VirusTotal gave me no detections: https://www.virustotal.com/gui/file/bac2bb4d0dac58e5563b47e6e63f3b332caba11da065861269e87ebc249f34e9/detection
I tried using deobfuscation tools to no avail. This isn't really more forte so I'm hoping someone with more experience can help me figure out what this code does and how it might have been triggered by an attacker.
All help is very much appreciated as it'll be huge for understanding what kind of access may have been gained.