Users have the ability to upload certificates for arbitrary names without proving domain control.
When you say you were right, are you saying Cloudflare allows that?
[1] https://community.letsencrypt.org/t/2018-01-09-issue-with-tl...