Don't be so sure. If they didn't disclose this to their buyers they are guilty of fraud. The statute of limitations has probably run out (I don't know which state has jurisdiction here), but delayed discovery rules may apply.
If I were a betting man, I'd bet the buyer knew about the issue and basically didn't care.
This is negligent. If they are running banking ecommerce infrastructure and are unable to deal with 101 security risks then it is absolutely negligent. The "it is too complex for the average person" isn't an adequate defense.
The only thing is that there has to be someone who lost something of real value for it to go to court as negligence does it not?
In your contact with companies you should say "Failing to fix this issue would be a violation of reasonably assumed security practices as required in LAW..."
Wouldn't the FTC want to know about this though, as this would be a great way to execute a pump-and-dump scam...