Skip to content
theregister·

🔒Click To Pray App Leaks 719K Users' Data

Vatican-Linked Prayer App Exposed Millions of Accounts

TL;DR

The Click To Pray app has exposed user data for over 719K accounts due to a critical security flaw. The vulnerability allows unauthorized access to personal information such as names and email addresses.

Click To Pray, a prayer app linked to the Pope's Worldwide Prayer Network, has leaked sensitive information from nearly 720,000 user accounts. This happened because of an Insecure Direct Object Reference (IDOR) bug that lets anyone access another user’s data without proper authorization checks. The API endpoint GET https://api.clicktopray.org/user/users/{id} returns full details for any account with a valid five-digit ID. All this exposed data, including email addresses and dates of birth, is now at risk of misuse by attackers. This breach could lead to phishing attacks targeting older users who may not be tech-savvy but trust the Vatican-related source. The Pope's Worldwide Prayer Network was informed about this vulnerability six months ago by an ethical hacker but failed to address it promptly. The exposed data includes validation hashes that can be used to verify accounts without receiving confirmation emails, making phishing attempts even more plausible. This incident highlights a significant security lapse in the app’s design and implementation. The Click To Pray app has 719,517 registered users as of July 2026, all potentially affected by this vulnerability.

Click To Pray App Leaks 719K Users' Data — theregister

Key Points

1

The Click To Pray app has leaked data for 719,517 registered accounts as of July 2026.

2

An Insecure Direct Object Reference (IDOR) bug allows unauthorized access to user information via API endpoint GET https://api.clicktopray.org/user/users/{id}.

3

The exposed data includes names, email addresses, country, dates of birth, and account deletion status for all users.

4

Ethical hacker reported the vulnerability six months ago but received no response from the Pope's Worldwide Prayer Network.

5

Validation hashes returned in sign-up responses can be used to verify accounts without receiving confirmation emails.

Why It Matters

The Click To Pray app’s security breach exposes sensitive data for nearly 720,000 users. This flaw allows anyone to access personal information such as email addresses and dates of birth via a simple API request. The lack of authorization checks makes phishing attacks highly likely, especially targeting older individuals who may trust Vatican-related sources. This incident underscores the critical need for robust security measures in applications handling sensitive user data.

prayer appdata breachIDOR buguser privacyphishing

Frequently Asked Questions

Why does this matter?

The Click To Pray app’s security breach exposes sensitive data for nearly 720,000 users. This flaw allows anyone to access personal information such as email addresses and dates of birth via a simple API request. The lack of authorization checks makes phishing attacks highly likely, especially targeting older individuals who may trust Vatican-related sources. This incident underscores the critical need for robust security measures in applications handling sensitive user data.

What happened?

The Click To Pray app has exposed user data for over 719K accounts due to a critical security flaw. The vulnerability allows unauthorized access to personal information such as names and email addresses.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 2,253 builders reading daily.

Also get