They should just multiply a base rate against the severity level. Say the base rate is ranged so low-severity stuff is $500-1K base but high-severity stuff is $10K base. That would net a researcher ~$88K for this specific bug (8.8 severity).
CVE severity is a terrible way to do this. If you follow the cybersecurity space you should know why.
That would create a perverse incentive to inflate the severity levels even more than they already are