There's no exploit, it's simply the fact that no form of spam prevention is required to make an account, therefore it's very easy for any botnet to register accounts and post spam. All they need to do is require a captcha on account creation, then the problem will be solved.
EDIT: Oh look, it's Love Specialist Baba Ji