In the next 12-18 months thereโs really never been a better time to make a million dollars doing bug bounties. If I was young and poor I would be locking myself in a room from now until this time next year and making finding a reproducible methodology or way of hacking that I can scale my primary and only objective in life.
If you find a stored XSS that auto-executes for many users but canโt be escalated further, it may still be abused for user-level availability impact by poisoning cookies at scale, causing requests to fail due to header size limits.
When trying to escalate XSS and you don't find a way to do so (cookies protected, sensitive requests protected with otp etc..)
Worst case scenario is escalating it to DoS
Which is fun and works most of the time + can increase severity a little bit since A vector will be set