The Vatican-affiliated Click to Pray website and mobile app exposed personal data for more than 700,000 users through an insecure direct object reference (IDOR) vulnerability in a publicly accessible API endpoint. Reports said anyone with a browser could enumerate sequential user IDs and retrieve plaintext account details without authorization, affecting roughly 719,517 accounts tied to the Pope’s Worldwide Prayer Network, including staff and administrative users. Exposed information included names, email addresses, country codes, dates of birth, account deletion status, and indicators showing whether an account had administrative privileges.
Researcher BobDaHacker said the flaw was reported on January 3 and remained live for at least six months, with independent verification indicating it was still exposed at publication. Additional reporting said the app’s sign-up process returned the validation_hash used for email verification, allowing attackers to validate accounts for arbitrary email addresses before legitimate users received the message, while official verification emails reportedly failed domain authentication checks. The platform, owned by the Pope’s Worldwide Prayer Network and developed by La Machi Communication for Good Causes, now faces heightened risk of phishing and social-engineering attacks impersonating Vatican-linked organizations.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Tom's Hardware reported that after Dark Reading sought comment and published its story, the Click To Pray app's exposed API and related security issues were reportedly remediated. This marks the first reported fix after more than six months of unresolved exposure.
Reporting revealed that the platform's sign-up endpoint returned the validation_hash used for email verification, allowing attackers to verify accounts tied to arbitrary email addresses before legitimate recipients received the message. The same report said Click To Pray verification emails failed domain authentication checks, increasing phishing risk.
At the time of publication, the Click To Pray API still exposed personal data from more than 700,000 accounts, including names, email addresses, country information, and account status, through unauthenticated enumeration of sequential user IDs. Reporting also noted exposure affecting staff and administrative accounts tied to the Pope’s Worldwide Prayer Network.
A researcher identified and reported an insecure direct object reference vulnerability in the Vatican-affiliated Click To Pray platform. According to the report, the issue was disclosed on January 3 but remained unresolved for months.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
8 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcecysecurity.news
Open sourcecybersecuritynews.com
Open sourcetomshardware.com
Open sourcescworld.com
Open sourcedarkreading.com
Open sourcebobdahacker.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.