Well, I didn’t get verified but I still have an XSS button for now

comments (single view)

The custom button runs the bookmarklet "javascript:(function()%7B%24nuxt.%24auth.user.name%20%3D%20%60oren%60%7D)()%3B"

It's only client side though

View all comments