Skip to content
AI News

Daily AI News for Builders

The stories worth reading, for builders and indie hackers. Updated all day.

The daily that does your AI homework.

One email, 7am, free. Reads in 5 minutes.

Click To Pray App Leaks 719K Users' Data
tech

Click To Pray App Leaks 719K Users' Data

Click To Pray, a prayer app linked to the Pope's Worldwide Prayer Network, has leaked sensitive information from nearly 720,000 user accounts. This happened because of an Insecure Direct Object Reference (IDOR) bug that lets anyone access another user’s data without proper authorization checks. The API endpoint GET https://api.clicktopray.org/user/users/{id} returns full details for any account with a valid five-digit ID. All this exposed data, including email addresses and dates of birth, is now at risk of misuse by attackers. This breach could lead to phishing attacks targeting older users who may not be tech-savvy but trust the Vatican-related source. The Pope's Worldwide Prayer Network was informed about this vulnerability six months ago by an ethical hacker but failed to address it promptly. The exposed data includes validation hashes that can be used to verify accounts without receiving confirmation emails, making phishing attempts even more plausible. This incident highlights a significant security lapse in the app’s design and implementation. The Click To Pray app has 719,517 registered users as of July 2026, all potentially affected by this vulnerability.

Jul 24, 2026 · 3 min read
Page 1 of 452