Tailscale solved my remote access for me when I travel, but I, and my kids who live in other states, have never had a problem with remote access to my Plex. They didn't even know I switch to T-Mobile for my internet. I saw this video (https://www.youtube.com/watch?v=6YWH3L5eiYg&t=808s) from Peter Carcion who talks about using a DDNS service to get around the double NAT problem. I've had a Dyn account for years, but I'm guessing it works the same way as what Peter lays out in his video.
Like Peter, I turned off the Wi-Fi on the T-Mobile gateway/modem, and also have a Netgear Orbi router system that all of my wired and Wi-Fi devices connect to. The Orbi router connects to the T-Mobile gateway via an Ethernet cable.
In the advanced section of my Orbi router, I made/added Dynamic DNS info for my Dyn account, and in the port forwarding the made a port forwarding assignment for port 32400 so it points to the IP address of my QNAP NAS, where I run Plex on.
I haven't a clue on how and why it works, but I do know, it works. The only difference in my setup and Peter's is I use 'Dyn' for my Dynamic DNS, and he uses 'No-IP'.
FYI, I reserve IP addresses of all of my devices on my router so they always use the same IP.