According to the official changelog, it was just a 2FA bug. No risk of loss of funds if you have a strong password.
Having said that, BTCPay did the right thing by labeling it as a vulnerability, and I'd rather have them inflate its severity than try to downplay it. I wouldn't call it "critical", but I have no qualms about our difference of opinion.
Besides, there are probably some people out there who are using admin/password1 and were only not pwned because they had 2FA enabled. For them, yeah, it's critical.
