Just because you can't do it doesn't mean it is fixed.
If you submit just the right from data you can probably corrupt the address in a predictable way. I don't think they mean just entering in a bogus address somewhere.
Luckily, I was completely wrong, and all is well. Sorry for anyone who panicked. I wasn't expecting it to get published so quickly without further discussion. I didn't even provide the screen shots at that time. It's all rather embarrassing. Mr Zee Kane took charge when he woke up and we worked through it once I got some key movers to endorse him. I didn't want to spread the apparent weakness to those who might take advantage of it. I was hasty in following advise to make it more widely known, and they were hasty to publish straight away without further discussion.
The account I was given access to was set-up against an email synonym I didn't know about, and Paypal never bothered to verify the email address. It's not my account though, someone else's name, address, and other details. A bit nefarious but not a security issue unless you plan to open a account with someone else's email address. Now, I'm not sure who's the hacker and who's the victim! I plan to request that Paypal disable the account, or at least remove my email from it, and if they refuse I will change the email myself.