I have no idea. Adding a single HTTP header seems simple to me, but I have no idea what their architecture looks like. It took them an entire month to send me a "thanks, we're working on it" email and that was only after I followed up with them.
Probably because you can't do much by exploiting this security hole besides annoying people, so there's little incentive to do so. If you can get me to click on an item and buy it, the item will be shipped to my physical address, not yours. Even if was a product you were selling, I could return it for a refund and your account would be charged back. It doesn't seem like a very profitable scheme.