Google has a well known WiFi API that can be used to identify exact location. It would not surprise me if google play services used this to scan your location even with location services for google play apps disabled.
WiFi is an attack vector that can be effectively mitigated with MAC randomization (enabled by default) and a VPN (which encrypts web traffic and DNS request(s). The prospect of MITM (man in the middle) attacks over wifi is a possibility but obviously this is highly unlikely for most users, and to be fair, a phone is not an easy target for most exploits over wifi compared to something like a windows PC.
The risks of wifi on are as follows;
-Digital forensics (if your phone is seized its network traffic can be monitored and discovered- wifi networks can be used to determine your previous locations too)
-Location API from google as stated before
-Connection records on WiFi hubs (but mitigated through pixel 7 MAC randomization)
-MITM attacks over wifi (not as prevalent in modern day networking)
The risks are present but unlikely for most users. The attack vector(s) does/do exist, and setting the disabling of wifi to be lets say 24 hours wouldn't do any harm in my opinion.
Its the same as auto reset- I have this at 24 hours as I use the alarm clock on my phone. If I'm not using the alarm within 24 hours then I have either slept too long or lost my phone!