My problem is really the company should probably have 24/7/365 security support standing by given the industry. I sent in two reports but I never got a confirmation email for either. The original item(to emphasize I never published anything on the site, this item was posted by another user and I was actually interested in purchasing it until I got redirected) which I have reported by phone and by form is still up on their site redirecting users. This one redirect doesn't actually appear malicious though but I have no way of telling how many other items are affected. At some point I feel there is a moral obligation for me to disclose the information which leads me to my second problem.
I have no fucking idea if I'm just overly worried (judging by the comments it would seem so) about the vulnerability. I also have no real idea of how serious it is. But it seems to me that even if a fraction of a fraction of transactions are affected it would still amount to a large amount of stolen information.
What I would really like is for them to email me back and say either "Oh wow yeah thanks for catching that" or "God damn you dumbass, no that's not actually a problem because xyz"