You can't make this up. Nomx is now claiming that their un-authenticated CSRF leading to admin privileges on a public URL poses "non-existing threat" because "the user must visit a hacked website".
https://www.infosecurity-magazine.com/news/nomx-researchers-defend-unfair-test/
That's it. CSRF is solved folks! You wanted to rework the OWASP Top 10 anyway, no?