I just read this:
same-origin policy allows inter-origin HTTP requests with GET and POST methods but denies inter-origin PUT and DELETE requests
What is so special about PUT/DELETE? Why are they blocked? You can do an update/delete inside a POST method anyway.
With CORS, why is a POST request preflighted if it uses xml/json rather than application/x-www-form-urlencoded?
Please explain why some verbs are treated differently to others.