Joshua Martinelle

Joshua Martinelle is a security researcher credited with 22 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #234 of 3,515 contributors. Their disclosures were published between 2022 and 2026. The most productive year was 2023, with 16 findings.

Their research concentrates on SQL Injection, which accounts for 13 of their findings (59%). Other recurring categories include Cross-Site Scripting, Deserialization Of Untrusted Data. The average CVSS score across these disclosures is 7.5, peaking at 9.8. Severity breakdown: 4 critical and 7 high.

The most affected software includes Bulk Price Update for Woocommerce (1), Easy Digital Downloads (1), Events Made Easy (1), across 22 distinct plugins, themes and core versions in total.

20 of the 22 disclosed issues have a vendor fix, while 2 remain unpatched. The most severe finding, "Gift Cards (Gift Vouchers and Packages) <= 4.3.2 - Unauthenticated SQL Injection", scores 9.8 out of 10.

20222023202420252026
Critical
High
Medium
Low
Global Rank

#234

of 3,515 researchers

Vulns

22

Critical4
High7
Medium11
Low0
Affected Assets

22

22plugins
Avg CVSS

7.5

Average score of vulnerabilities

Researcher Submissions

22 records
2026-07-29 00:00CVE-2026-18197
6.1
Medium
Joshua MartinelleYes
2026-05-20 00:00CVE-2026-9065
4.9
Medium
Joshua MartinelleYes
2026-05-20 00:00CVE-2026-9059
4.9
Medium
Joshua MartinelleYes
2024-12-02 00:00CVE-2024-12015
6.5
Medium
Joshua MartinelleYes
2024-01-31 00:00CVE-2024-1061
6.5
Medium
Joshua MartinelleYes
2023-04-19 00:00CVE-2023-26325
8.8
High
Joshua MartinelleYes
2023-03-29 00:00CVE-2023-28662
9.8
Critical
Joshua MartinelleYes
2023-03-22 00:00CVE-2023-28665
6.1
Medium
Joshua MartinelleYes
2023-03-22 00:00CVE-2023-28659
8.8
High
Joshua MartinelleNo
2023-03-20 00:00CVE-2023-28666
6.1
Medium
Joshua MartinelleYes
Showing 1–10 of 22 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C