The simple-fields plugin prior to 1.2 for WordPress has CSRF in the admin interface.
simple fields project simple fields