I expect my PDF reader to be secure. If the PDF format is too complex to implement safely then the renderer should be sandboxed in the reader itself instead of preventing me from scripting using xdotool and similar.
And unless you fully sandbox your PDF reader then an exploit is going to have access to your user directory without any display server involvement anyway. X11 vs. Wayland doesn't even come into the picture.