Vatican’s Click To Pray App Exposed 719,000 Users via IDOR Flaw
Even a prayer app proved unable to keep others’ secrets. Click To Pray, the official app of the Pope’s Worldwide Prayer Network, exposed the names, email addresses, and other data of hundreds of thousands of users. The cause was a simple flaw in its access system.
A security researcher using the alias BobDaHacker found the problem. By her account, she reported the vulnerability to the service’s owners on 3 January, yet six months passed with no response.
A Wide Reach and a Simple Flaw
Click To Pray runs on iOS, Android, and the web. It supports seven languages and helps users unite in prayer for the Pope’s intentions. By July 2026, some 719,517 people had registered with the service.
The vulnerability was an insecure direct object reference, or IDOR. The server accepted an account number and returned the details linked to it. However, it never checked whether the person making the request had any right to view another user’s data.
The design made abuse trivial. After registration, Click To Pray assigned each user a sequential numeric identifier. Substituting a different five-digit number into the request was enough to pull the matching account’s information, as BobDaHacker documented in her write-up.
What the Service Leaked
The exposed fields were extensive. They included the email address, first name, surname, country, date of birth, and a profile-deletion marker.
Worse still, nothing limited the number of requests. Therefore, an attacker could iterate through every identifier in turn and harvest the data of all 719,517 users.
An Attractive Target for Phishing
BobDaHacker called such a database especially appealing to those who craft fake emails. Many of the app’s users are elderly, and they may trust messages framed as coming from the Vatican or the Pope. A scammer would only need to send a note urging an urgent click on a link, using the recipient’s already-known name and address.
Two More Weaknesses
The researcher also found a problem in the registration mechanism. The server returned the secret account-confirmation code in its response. The same code appeared in the link within the confirmation email. Consequently, an outsider could register with someone else’s address and confirm the profile before the real mailbox owner did.
Click To Pray’s own emails created further risk. BobDaHacker’s mail client warned that the genuine confirmation message failed domain authentication and could have been forged. As a result, a fraudulent email could look no less convincing than the official one.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.