Vatican prayer app leaks 700,000 users' personal data
This digest was compiled by AI from multiple sources — links to the originals are below.

A vulnerability in the Vatican's official prayer app, Click to Pray, exposed the names, email addresses, and countries of more than 700,000 users. The flaw, discovered by a white-hat hacker in January, remains unpatched as of publication, allowing anyone with a browser to access the data.
The Vulnerability
The flaw is an insecure direct object reference (IDOR) in the API endpoint of clicktopray.org. Anyone can query the endpoint with a user ID to retrieve personal information, including names, email addresses, and country codes, without authentication. The lowest user IDs correspond to staff accounts, which also reveal administrative privileges.
Data Exposure
More than 700,000 user accounts are freely accessible. Each record includes a sequential user ID, name, email, country, account status (active or deleted), and role (e.g., 'PRAYER' for regular users). The data is in plaintext and can be scraped with a simple script, enabling mass phishing or social engineering attacks.
Response Efforts
Dark Reading confirmed the vulnerability independently and contacted the Pope's Worldwide Prayer Network, which runs the app, to facilitate a fix. The organization did not respond. The communications firm La Machi, which developed the app, also did not comment. The issue remains live as of publication.
What's Next
The Pope's Worldwide Prayer Network has not announced a timeline for patching the vulnerability. It remains unclear whether the exposed data has been exploited by malicious actors.
2 sources
Vatican prayer app leaks 700,000 users' personal data



