It's not remotely exploitable --- it requires installing a malicious app; that makes it far less severe than something that could be done through e.g. just visiting a webpage.
Post some screenshots of the app with screenshots of some random Paypal transfers and I don't think that you will have a problem getting people to find/download your app.
Downloading and running it once would set up the exploit but not complete it, IIRC. You need to go back to the target app and re-enter credentials then run the exploit app a second time. So a broken app that a user would run once and then delete is no good.
A standard Trojan game/utility would work fine even if only a small number of people run it.
Yes, they submitted one app which was accepted. That app is now gone, you can bet. Can they continue to submit apps continuously which Apple will still accept? I doubt it. The story isn't clear on this.
I bet it was submitted before they informed Apple of the problem. If you were to submit such an app today, it seems likely that they now look for stuff like this.
This is something many people forget: Apple has a challenge changing system APIs since they need to avoid breaking other apps but they can start scanning App Store submissions immediately and take action with absolute certainty that there won't be collateral damage.
It also works if the target has installed an exploitable app, or one that can be trojaned via an included component. That sort of thing has happened in the past even from "reputable" software vendors (c.f. Lenovo/Superfish or the Sony rootkit), so pretending that it can't happen on App Store seems naive to me.
No, this isn't a remote root, but it's pretty severe and not something that should be downplayed with italics.