Celestial Data Conundrums
Click To Pray, a prayer app endorsed by the Holy Father himself, somehow managed to leak individuals’ names and email addresses for months. Top marks for privacy, right? This app needs to be more discreet regarding your information. It’s available in seven languages and can be accessed on iOS, Android, and clicktopray.org. As of July 2026, it boasts 719,517 accounts – and one colossal breach, thanks to a clever individual named BobDaHacker. She identified this flaw and alerted the Pope’s tech team on January 3, but they seemed to be too engrossed in prayer to take notice. “Vulnerability still exists,” she tweeted. “Never received a response. Perhaps my message wasn’t heavenly enough.”
BobDaHacker Strikes Again
Our tech guru, BobDaHacker, is the same genius who uncovered a flaw in McDonald’s ordering system and some unsecured controls on Chinese robot manufacturer Pudu Robotics. This latest debacle involves an Insecure Direct Object Reference (IDOR) bug in the prayer app. Imagine it like your mom handing you the incorrect house keys; the app believes it’s supplying your details but is actually revealing someone else’s instead. “You request your information, server says ‘here it is’. Request someone else’s, server responds ‘here it is’ again. Apparently, you shall not authorize,” Bob quips.
IDs as Sacred as Swiss Cheese
When you create a Click To Pray account, the app assigns a simple numeric user ID. BobDaHacker discovered that the API endpoint GET https://api[.]clicktopray.org/user/users/{id} dispenses user information for any account as long as you possess the correct five-digit ID. No checks, no balances. “Just keep track of the digits and swipe someone else’s information,” she noted. It’s like a smorgasbord of email addresses, names, countries, birthdays, and more, all up for grabs without needing to be Inspector Gadget.
A Clever Phishing Haven
BobDaHacker raises a concerning issue: these users might not be the most tech-savvy, placing their trust in anything bearing the Vatican’s seal, transforming it into a “phishing treasure trove.” Imagine an email stating, “The Holy Father requires your immediate assistance!” with a Vatican-style link. Grandma’s clicking that without hesitation. You’d think it couldn’t worsen, but it does. The signup endpoint, POST https://api.clicktopray.org/user/users/sign-up, returns the account’s validation_hash in the response body, the same UUID used in the email confirmation link. Someone could sign up with any email, validate it before the real email arrives in the inbox, and Bob’s your uncle! To make it worse, genuine verification emails get flagged by her email client for failing domain checks, potentially spoofed.
The Vatican’s Tech Crew: Missing in Action
GadgetLad reached out to the Pope’s Worldwide Prayer Network and heard nothing but silence. BobDaHacker is still hoping for a breakthrough there. Perhaps next time, folks.
Summary: Sacred Data Breach, Batman!
What a disaster this is. The Pope’s app has a vulnerability large enough to accommodate a bus, and it’s leaking user information like confessionals after Sunday service. With such security missteps, it may be time for the Vatican to seek some divine IT assistance.