It turns out, I was misled. There's an additional vulnerability that is serious. Patch now if you haven't already.
The BTCPay authors intentionally wrote a deceptive changelog that omitted the important vulnerability while only mentioning the 2FA fix, making it look like that was the "critical vulnerability" (since it was the only vulnerability mentioned).
My evidence for this is a combination of the aforementioned release notes and the blog where they say the vulnerability would "allow an unauthenticated remote attacker to obtain .macaroon credential files for LND".
Security Advisory: Update BTCPay Server to 2.4.2 Immediately | BTCPay Server Blog
Official BTCPay Server Blog