I understand, but that sort of behaviour should have been thwarted quickly by their security team or policies setup against abuse.
Also, the ability to impersonate people (not just celebrities) should require at least manual approvals. Not sure why this ability even exists.
The original speculation (that it was an API vulnerability) is actually easier to stomach.