The real answer is, there are countless instances of various old-school forum software running all over the internet with either no passwords at all, or that allow free, anonymous, unverified signup. Heck, over the decades I've orphaned at least two fitting that exact description. They died a natural death since the likes of Facebook and Twitter basically killed semi-private forums wholesale, but I couldn't be bothered to actually take them down.
This isn't a matter of rogue agents hacking, it's more like long-forgotten technical debt; but not even that, really - We just didn't care 20 years ago. They're making use of sites designed to explicitly allow exactly what they're doing.
In this case, though, it sounds like the real "exploit" was finding a site that allows posting messages encoded right in the URL via a GET. Not an exploit of those sites, because again, we used to not care and that was a feature not a bug; rather, it was an exploit of their own shackles, but what they did with it was largely allowed by design.