Can you clarify exactly when you reported this XSS as a personal friend of mine reported it (exact same bug with a slightly different XSS vector) and was told it had already been found a reasonable while back.
(From memory, he also took a few photos of it also).
Would be interested to hear your response as it might give this another angle entirely, haha.
My personal experience with PayPal isn't particularly great, I'm a security researcher who's just turned 18, and even when I was underage I never actually disclosed that but regardless I had the following knocked back;
(Whole heap of non-critical XSS's, and two critical stored ones, The ability to edit titles on some PayPal subdomains (without giving too much information out) - This vulnerability still exists but I was told it was quote "not serious" even though the title field was vulnerable to stored XSS.
Full path disclosures, open administrative panels, whole variety of cookie/SSL/TSL based issues which I was told did not warrant a bounty.
Also had a personal friend (the same guy who found the XSS you've posted here) find a couple SQLi's on a few PayPal domains (post-auth) and he still hasn't heard back from them.
I'm not going to be the guy to accuse PayPal of not playing fair here, but my friend has also reported vulnerabilities I had previously reported and gotten paid for them. (Might be because he reports them from his security company email, whereas I was reporting them as an individual).
Anyway, Sad to hear you didn't get a bounty!
Also, if you don't have it here's a pretty good bug bounty list; http://bugcrowd.com/list-of-bug-bounty-programs/