Hi Dawn,
Thanks for contacting us — we take security very seriously and will of course investigate and report back to you 🙂
We did already receive a very similar report earlier today (though it seemed to be from a different person) by email and have already begun to work on this, so we should be able to update you before too long.
I would like to take a moment to note that email is indeed our preferred means of dealing with reports like this: as you can imagine, if a report containing valid methods of compromising a website are posted publicly the results may be less than satisfactory for a great many website operators. For that reason, I have redacted your post and removed any details from public view.
Thanks again for highlighting this and we’ll update you with our findings in due course.