The CSRF vulnerability is not classified as critical as it relies on people being misled into clicking links which performs actions which were not intended. This vulnerability is present in a lot of scripts.
As long as you, your admins, and your moderators are smart ("web-smart"), there is no need to patch vBulletin.
The patch is extensive, if it was not, a "patch level (PL)" release could have been made.
|