← BACK TO FEED
TAG

vatican1 article

Pope's Prayer App Exposes 700,000 Users Because Nobody Bothered to Check Auth

The Pope's official prayer app, Click To Pray, has exposed the personal data of over 700,000 users — including names, email addresses, and dates of birth — due to a basic security flaw known as an Insecure Direct Object Reference (IDOR) bug, which allows anyone to access any user's data simply by changing a number in the API request. Ethical hacker BobDaHacker discovered and reported the vulnerability six months ago but has received no response from the Pope's Worldwide Prayer Network, and the flaw remains unpatched. The situation is made worse by additional security weaknesses in the signup process and poor email authentication, leaving users — many likely elderly and trusting of Vatican-affiliated communications — highly vulnerable to phishing attacks.

25 Jul 2026