Design Import/Export – Styles, Templates, Template Parts and Patterns
Design Import/Export – Styles, Templates, Template Parts and Patterns has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.9, and the most serious one scores 4.9 out of 10.
The most common weakness is SQL Injection, behind 1 of the records (100%).
The one issue recorded for Design Import/Export – Styles, Templates, Template Parts and Patterns has a vendor fix available, so running the current release closes it.
All of these findings were reported by ChamlaVic. Design Import/Export – Styles, Templates, Template Parts and Patterns is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-14050Design Import/Export <= 2.2 - Authenticated (Administrator+) SQL Injection via XML File Import
Read the full analysisVulnerability Records

Design Import/Export – Styles, Templates, Template Parts and Patterns
Author
UXL Themes
Import and export your block based theme design: global/custom styles, templates, template parts and patterns. Easily move your custom full site editing theme design from one website to another, or from a local installation to a live site. Ideal for designers and developers working with the Site Editor and a block based full-site-editing theme, who have edited their block based custom styles, templates, template parts and patterns, and now need to copy that design over to a new WordPress installation. The Design Import/Export plugin allows this to be done with minimal fuss, and can also be used to take regular backups of your block theme based design(s). Works with any full-site-editing block theme. License Licensed under the GNU General Public License v2.0, http://www.gnu.org/licenses/gpl-2.0.html
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C