The Click To Pray app, which has the endorsement of the Pope and serves hundreds of thousands of users globally, has reportedly leaked personal information, including names and email addresses, for an extended period. This security issue was identified by ethical hacker BobDaHacker, who disclosed the vulnerability to the Pope’s Worldwide Prayer Network six months ago but has not received any response.
Details of the Vulnerability
The vulnerability stems from an Insecure Direct Object Reference (IDOR) flaw. This type of security weakness allows unauthorized access to user data. According to BobDaHacker, the app’s API endpoint does not perform necessary authorization checks, meaning that a user can access data belonging to any account simply by providing a valid user ID.
Scope of the Data Leak
As of July 2026, the Click To Pray app has approximately 719,517 registered accounts. The exposed data includes users’ email addresses, names, countries, dates of birth, and account status. The lack of rate limiting allows an attacker to enumerate all accounts easily, which poses a significant risk of phishing attacks targeting potentially vulnerable users.
Potential Impact on Users
Many users of the app may be older individuals who are less tech-savvy and more trusting of communications from the Vatican. BobDaHacker noted that this demographic could be particularly susceptible to phishing attempts, especially if they receive emails that appear to be from the Pope or the prayer app.
Additional Security Concerns
Further complicating matters, the app’s signup process exposes a validation hash that could allow an attacker to verify accounts using any email address. BobDaHacker highlighted that the legitimate emails from Click To Pray may also appear suspicious due to authentication failures, making it easier for attackers to craft convincing phishing emails.
Despite multiple attempts to contact the Pope’s Worldwide Prayer Network for comment, no response has been received. The ongoing nature of this vulnerability raises concerns about the app’s commitment to user privacy and security.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








