Theregister
Vatican Prayer App Exposes 700K Users' Personal Information
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Click To Pray app, endorsed by the Pope, has leaked over 700,000 users' personal information due to an Insecure Direct Object Reference (IDOR) vulnerability. Discovered by ethical hacker BobDaHacker in January 2026, the flaw allows anyone to access names, email addresses, and account statuses without authorization. Despite reporting the issue to the Pope's Worldwide Prayer Network, no response or fix has been implemented. The app's API exposes user data in plaintext, making it susceptible to phishing attacks, especially targeting older, less tech-savvy individuals. The vulnerability remains active as of July 2026, with the potential for mass exploitation through simple scripts. The app has approximately 719,517 registered accounts, and the issue has persisted for months without resolution.
Key Points: • Over 700,000 users' personal information leaked from the Click To Pray app. • The vulnerability is an Insecure Direct Object Reference (IDOR) allowing unauthorized data access. • No response or fix has been provided by the Pope's Worldwide Prayer Network since the issue was reported.