Isn't this easily mitigated by making all request that change state (update data in any way) as post requests?
It's slightly harder to exploit, as the attacker can't just send you a link to facebook.com, but they can send you a link to example.com which has the form and uses JavaScript to submit the form.
<script>document.forms[0].submit();</script>
(The above code may contain bugs.)