I think:
* Most devs are at least full stack
* Most apps now-a-days interact directly/indirectly with browser
* Attributing this problem to frontend devs without understanding why CORS and issues in handling that, makes you unaware of security issues with your backend services.
FYI: I am a backend developer.