The plugin includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin
id: CVE-2022-4321
info:
name: PDF Generator for WordPress < 1.1.2 - Cross Site Scripting
author
...