No, it's entirely the fault of GET. They're opening an iframe on their page with a source your post URL. If it were POST-only, they'd be blocked by Javascript being unable to communicate across domains.
Also, sure, every webserver could proxy the requests—but then you have to guarantee that you haven't created an open proxy, which is a much worse hole than a simple CSRF—and then you have to do some more server-side configuration every time you want to enable your views to touch a new third-party API—which excludes a lot of hosted sites, like blogs, from using any API that their server admin hasn't considered.