I doubt the "black market" would pay much of anything for this bug, because, like most severe web vulnerabilities, it has no half-life.
The half-life of this bug is ~0. As soon as Facebook becomes aware of it, it is nearly instantly fixed everywhere. This is very not the case if you get e.g. code execution on a version of Java which will take 50 months to completely disappear from the wild.