The user-domain-whitelist plugin prior to 1.5 for WordPress has CSRF.
user domain whitelist project user domain whitelist