Vatican Prayer App Exposes 700K Users' Personal Information

Vatican Prayer App Exposes 700K Users' Personal Information

First seen 24 Jul 2026, 22:49 UTC DarkreadingTheregisterScworld 86% similarity 66.0

Article Content

Browse articles
ThreatCluster

The Click To Pray app, endorsed by the Pope, has leaked over 700,000 users' personal information due to an Insecure Direct Object Reference (IDOR) vulnerability. Discovered by ethical hacker BobDaHacker in January 2026, the flaw allows anyone to access names, email addresses, and account statuses without authorization. Despite reporting the issue to the Pope's Worldwide Prayer Network, no response or fix has been implemented. The app's API exposes user data in plaintext, making it susceptible to phishing attacks, especially targeting older, less tech-savvy individuals. The vulnerability remains active as of July 2026, with the potential for mass exploitation through simple scripts. The app has approximately 719,517 registered accounts, and the issue has persisted for months without resolution.

Key Points: • Over 700,000 users' personal information leaked from the Click To Pray app. • The vulnerability is an Insecure Direct Object Reference (IDOR) allowing unauthorized data access. • No response or fix has been provided by the Pope's Worldwide Prayer Network since the issue was reported.

ThreatCluster AI

Timeline

2026-01-03
Vulnerability discovered by BobDaHacker
BobDaHacker identified the IDOR vulnerability in the Click To Pray app and reported it to the Pope's Worldwide Prayer Network.
Theregister
2026-07-24
Dark Reading confirms vulnerability remains live
Dark Reading independently verified that the IDOR vulnerability is still active, exposing user data without authorization.
Darkreading
2026-07-24
Articles published detailing the breach
Both Dark Reading and The Register published articles highlighting the ongoing data leak and lack of response from the Vatican's app developers.
Darkreading

Community

Browse all →