Nope, POST does not prevent this kind of thing -- it's just as easy to forge a POST as a GET. See http://en.wikipedia.org/wiki/Cross-site_request_forgery
To protect a site, you must include an unguessable parameter in all side-effecting requests.
To protect a site, you must include an unguessable parameter in all side-effecting requests.
And if you're going to be putting the session id somewhere, it should be in a POST request, not a GET request, otherwise it can be hijacked.
To fix the problem, PG needs to check that the userid that clicked the fnid is the same as the userid for which it was created.
BTW, browser bugs actually make the problem even more complex than this because it is sometimes possible to steal content off of other pages.