As a result, the firewall remains disabled only as long as the system is not rebooted. It re-enables on the next boot.
Seems OK with the ufw back end -- the kcm sets ENABLED=no in ufw.conf and the systemd service checks that on startup
Fixed by the commits in https://invent.kde.org/plasma/plasma-firewall/-/merge_requests/55, written by Lucas Biaggi!