“If you are logged in to a site that does this, it's a huge danger. Your private account information can be slurped down by ajax on any other sites.”
This is false (unless `Access-Control-Allow-Credentials` is set). See CORS 101: https://annevankesteren.nl/2012/12/cors-101