That implies that it's easier to get the password change email sent to an address with a different local part at the same domain than to a completely different domain.
@Alex Khomenko told me in another place, that there may be
a secondary authentication on password changes from the
forgotten password link, in the US PayPal. If true and
currently in place this would mean that the US is not
vulnerable, although they may still have the email bug
He said he doesn't use PayPal himself and that he only requested a change password link when he was trying to contact them about "effective spam". Perhaps he supplied them with one of his email addresses and it happened to have a counterpart at a different subdomain (like example@email.com vs example@email.com.au)?