Sign up for the Pope’s official prayer app, share your name and email, and join a global community of believers. Meanwhile, a security researcher reportedly changes a single number in a URL and pulls up your entire profile. That’s the alleged reality for up to 719,517 users of Click To Pray — the Vatican-backed app where the faithful share prayer intentions with the Holy Father. According to the researcher’s account, the flaw has been exploitable for at least six months, and the Pope’s Worldwide Prayer Network has not responded to multiple disclosure attempts.
A Flaw So Basic It Has a Name
An independent researcher reportedly found that Click To Pray’s backend hands over any user’s data to anyone who asks — no authorization required.
A researcher using the handle “BobDaHacker” claims to have discovered an insecure direct object reference, or IDOR. In plain terms: the app allegedly exposes numeric user IDs in URLs, and the server hands over any user’s profile data when asked — name, email address, and country of origin — with zero authorization checks applied.
The researcher says:
- The first disclosure attempt went to nine official email addresses on January 3.
- None replied.
- The vulnerability was reportedly still live at the time of publication.
Straight Arrow independently confirmed the flaw, and Dark Reading first reported it publicly. The Pope’s Worldwide Prayer Network did not respond to either outlet’s request for comment.
“One of the most basic access control flaws in web security,” the researcher wrote. “You ask for your own data, the server gives it to you. You ask for someone else’s data, the server gives you that too.”
OWASP — the standard framework developers actually reference for web security — flags this exact class of bug as a top-tier vulnerability. Its presence here suggests either no security testing, or testing that nobody acted on.
This isn’t Click To Pray’s first confession. In 2019, UK firm Fidus Information Security found that the app’s $110 Bluetooth eRosary was returning login PINs in plain text via its API. It took Fidus ten minutes to find it, according to The Register. A Vatican spokesperson confirmed that flaw was fixed. History, apparently, didn’t stick.
A Phishing Goldmine, Courtesy of the Holy See
Nearly 720,000 validated faith-community email addresses sit reportedly exposed — a scammer’s dream list.
Names and emails aren’t passwords. But 720,000 validated addresses belonging to people who specifically trusted a Vatican-branded app are exactly the kind of list that makes phishing campaigns effective. The researcher reportedly described the dataset as a “phishing goldmine.” The user base skews older and deeply trusting of anything stamped with the Pope’s name — making “The Holy Father requests your urgent attention” a remarkably plausible subject line.
This isn’t an isolated pattern in faith-based apps. Pray.com exposed data on up to 10 million users through misconfigured cloud storage, according to PCMag. Religious platforms routinely collect sensitive behavioral data and protect it poorly — and Click To Pray fits that mold.
Click To Pray operates internationally, collecting personally identifiable information from EU users — putting it squarely under GDPR obligations, including breach notification requirements. Whether regulators have been informed remains unknown. The Pope’s Worldwide Prayer Network has not commented publicly.
If you use Click To Pray, treat your registered email address as potentially compromised. Watch for phishing attempts using religious or Vatican-themed lures. Until the app’s operators break their silence, assume your data has had an audience you didn’t pray for.





























