It would have same impact because the referral domain would go unnoticed if an attacker claimed it and hosts a very similar site that distributes malware/paywalls.
The tweets was an extra layer of impact for this vulnerability. It would be still a P3 even without the tweets screenshot