Theregister Vatican Prayer App Exposes 700K Users' Personal Information
Article Content
- •Over 700,000 users' personal information leaked from the Click To Pray app.
- •The vulnerability is an Insecure Direct Object Reference (IDOR) allowing unauthorized data access.
- •No response or fix has been provided by the Pope's Worldwide Prayer Network since the issue was reported.
The Click To Pray app, endorsed by the Pope, has leaked over 700,000 users' personal information due to an Insecure Direct Object Reference (IDOR) vulnerability. Discovered by ethical hacker BobDaHacker in January 2026, the flaw allows anyone to access names, email addresses, and account statuses without authorization. Despite reporting the issue to the Pope's Worldwide Prayer Network, no response or fix has been implemented. The app's API exposes user data in plaintext, making it susceptible to phishing attacks, especially targeting older, less tech-savvy individuals. The vulnerability remains active as of July 2026, with the potential for mass exploitation through simple scripts. The app has approximately 719,517 registered accounts, and the issue has persisted for months without resolution.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (10)
Following this threat?
Track La Machi Communication in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Condé Nast User Data Breach: 32.8 Million Records for Sale On September 7, 2026, a database containing 32,815,767 user records from Condé Nast was listed for sale on a Russian-language hacker forum for $15,000. The data, reportedly collected between September and October 2025, includes unique email addresses, names, postal addresses, gender, birthdays, and phone numbers, but…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…