Uncaught exception 'PDOException'

They don’t have to use your form to send $_POST values - they can either create their own form to submit whatever they like or even intercept and change the values after your form is submitted.