I too also have a special place of hate for Rekordbox. However I'm somewhat confused by this vulnerability, isn't plug n play unauthenticated file access essentially a core feature of "PRO DJ LINK"? The security mitigation, and best practice, being to have the involved devices connected on a entirely private LAN. I've never tried connecting them to a "public" network.
The feature definitely does what it says it does, but I think that the mount is generally accessible outside the software may be where the “surprise” lies.
I definitely would not have used this feature on a public network or exposed the mount to the open internet as well.