Looks like it's been fixed. [Maybe]
Read where Paypal already claimed to have fixed it back in May, which turned out to be a falsehood. It also did not say for sure that they paid the Bug Bounty Hunter, and they have a reputation for ripping them off. Click the bug bounty tag here.