Honestly curious: how would you exploit it? If the pi isn't exposed to the www by your router, what can you do?
Scenario for attack: Laptop looks up a website, DNS request is made to pi-hole, pi-hole sends request to internet. Response packet received back is actually from an attacker, that uses a known vulnerability in the handling of the packet to take over the machine.
Attacker can now see what DNS requests are being made, and by returning custom responses, it can MITM any HTTP request you make from your laptop. Let's hope everything is encripted via TLS, and hope that some piece of software that just asked for admin permission didn't just install a new TLS trust root.
Essentially - it's reading user-defined data - which is probably enough to be really bad, incase of a malicious exploit in the wild.