AFAIK Pi-holes are almost always going to be sitting inside a LAN and owned by whoever owns the other devices on the network too, so the risk is quite low.
In general, yes, but this is how real issues start. Look at all the bmc software written in the world. It's utter horseshit. You are supposed to use a dedicated vlan for accessing the bmc. Everyone is still fighting the bmc software and it is routinely accessed over the open internet.
they should remedy that ;}
What is bmc software?
idrac, ilo, etc.
Yes definitely. My ISP does not allow me to expose a DNS server to the internet, they told me it was against the law. So it seems you'd have to break the law in my country in order to be vulnerable to this!
Huh, really? Against the law, or against the contract? In what country do you live?
I think it's more than 'pretty low issue'. Someone already connected to the LAN may just sniff the login credentials since the Pi-hole web interface doesn't use https and then gain root access where all LAN clients trust with their DNS queries.