Click To Pray: Pope’s prayer app leaks 700,000 user emails

Click To Pray: Pope’s prayer app leaks 700,000 user emails

Pope-Endorsed Prayer App Exposed 700K+ User Records for Months

A critical security flaw in Click To Pray a Vatican-backed prayer app with over 700,000 users left personal data exposed for at least six months. Ethical hacker BobDaHacker discovered an Insecure Direct Object Reference (IDOR) vulnerability in the app’s API, allowing unauthorized access to user records by manipulating sequential user IDs.

The unsecured endpoint (GET https://api.clicktopray.org/user/users/{id}) returned sensitive data for any account, including names, email addresses, countries, and dates of birth. With no rate limiting in place, an attacker could have scraped the entire database. Additionally, the app’s signup process generated validation hashes for any email, enabling potential account takeovers and increasing phishing risks particularly for users who trust Vatican-affiliated communications.

Despite the hacker’s report six months ago, the issue remained unaddressed until The Register exposed the flaw. The app’s own verification emails also lacked proper authentication, further heightening the risk of impersonation attacks. The incident underscores vulnerabilities in widely trusted platforms, even those with religious affiliations.

Source: https://www.scworld.com/brief/popes-prayer-app-leaks-700000-user-emails

Click To Pray TPRM report: https://www.rankiteo.com/company/pray.com

"id": "pra1785213395",
"linkid": "pray.com",
"type": "Vulnerability",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '700,000+',
                        'industry': 'Religious/Non-Profit',
                        'location': 'Vatican City',
                        'name': 'Click To Pray (Vatican-backed app)',
                        'size': '700,000+ users',
                        'type': 'Mobile Application'}],
 'attack_vector': 'Insecure Direct Object Reference (IDOR)',
 'data_breach': {'data_exfiltration': 'Potential (no evidence provided)',
                 'number_of_records_exposed': '700,000+',
                 'personally_identifiable_information': 'Names, email '
                                                        'addresses, dates of '
                                                        'birth, countries',
                 'sensitivity_of_data': 'High (names, emails, DOB, countries)',
                 'type_of_data_compromised': 'Personally Identifiable '
                                             'Information (PII)'},
 'description': 'A critical security flaw in *Click To Pray*, a Vatican-backed '
                'prayer app with over 700,000 users, left personal data '
                'exposed for at least six months. An Insecure Direct Object '
                'Reference (IDOR) vulnerability in the app’s API allowed '
                'unauthorized access to user records by manipulating '
                'sequential user IDs. The unsecured endpoint returned '
                'sensitive data, including names, email addresses, countries, '
                'and dates of birth. The app’s signup process also generated '
                'validation hashes for any email, enabling potential account '
                'takeovers and phishing risks.',
 'impact': {'brand_reputation_impact': 'Potential damage to Vatican-affiliated '
                                       'trust',
            'data_compromised': 'Names, email addresses, countries, dates of '
                                'birth',
            'identity_theft_risk': 'High (PII exposed)',
            'systems_affected': 'Click To Pray app API'},
 'motivation': 'Ethical disclosure',
 'post_incident_analysis': {'root_causes': 'Insecure API design, lack of rate '
                                           'limiting, improper email '
                                           'validation'},
 'references': [{'source': 'The Register'}],
 'threat_actor': 'Ethical hacker (BobDaHacker)',
 'title': 'Pope-Endorsed Prayer App Exposed 700K+ User Records for Months',
 'type': 'Data Exposure',
 'vulnerability_exploited': 'Insecure Direct Object Reference (IDOR), lack of '
                            'rate limiting, improper email validation'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.