The Modal Window WordPress plugin prior to 5.3.10 does not have CSRF check in place when bulk deleting modals, which could allow malicious users to make a logged in admin delete them via a CSRF attack