Click to Pray, Click to Leak: Pope's Official App Exposes 700k User Emails

miniBill1 pts0 comments

Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails | bobdahacker

🎄<br>Currently at 39C3 in Hamburg! Feel free to hit me up on my socials<br>💻

-->

Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails

July 24, 2026

BobDaHacker

I reported this on January 3rd, 2026. It is now July 24th. Six months later. The vulnerability is still live. Nobody has ever responded. I guess my email wasn't in their prayers.

What is Click To Pray?

Click To Pray is the official prayer app of the Pope's Worldwide Prayer Network. Pope Francis himself launched it during a Sunday Angelus address in St. Peter's Square back in 2019. He held up a tablet on the balcony and told the world to download it. Very cool. Very holy. Very leaky.

The app lets users pray alongside the Pope's monthly intentions, share prayer requests with the community, and follow a daily prayer rhythm. It's available on iOS, Android, and the web at clicktopray.org, in seven languages. As of July 2026, it has 719,517 registered accounts .

It's a Pontifical Work. This is Vatican infrastructure. God's tech stack, if you will.

The Vulnerability

When you create an account on Click To Pray, you're assigned a sequential numeric user ID. Simple enough.

The API endpoint GET https://api.clicktopray.org/user/users/{id} returns user data for any account when you supply a valid user ID. No authorization check. No ownership validation. Just increment the number and get someone else's data. The Lord provides.

Here's what the API hands back for user 69420 (nice):

Email address. First name. Last name. Country. Date of birth (or as their backend calls it, borned_date, because apparently bad grammar isn't a sacrament). Role. Whether the account has been deleted. All of it, for any user, no questions asked.

The role field is "PRAYER". Your role on the Pope's prayer app is prayer. Thank you, backend team.

The response headers also have X-Powered-By: Express because the Vatican is running its prayer infrastructure on the framework you learn in week two of a Node.js bootcamp.

That's an IDOR. Insecure Direct Object Reference. One of the most basic access control flaws in web security. You ask for your own data, the server gives it to you. You ask for someone else's data, the server gives you that too. Thou shalt not authorize, apparently.

The Scale

With sequential user IDs and no rate limiting, an attacker could enumerate every single account on the platform. All 719,517 of them. One GET request per user. for i in range(1, 719518): scrape(). That's it. That's the exploit.

That's 700,000+ email addresses belonging to people who signed up for an app to pray. A lot of these users are likely older, less tech-savvy, and deeply trusting of anything associated with the Vatican. A harvested list like this would be a phishing goldmine. Imagine getting an email that says "The Holy Father requests your urgent attention" with a Vatican-looking link. Grandma is clicking that. Every time.

But Wait, There's More

While poking around, I noticed something fun. The signup endpoint POST https://api.clicktopray.org/user/users/sign-up returns the account's validation_hash directly in the response body.

That validation_hash is the exact same UUID used in the email verification link:

So the API hands you the verification token before you even check your email. You can sign up with any email address and verify the account immediately without ever accessing the inbox. The verification email is just a suggestion at that point. Faith-based email verification, if you will.

Oh, and that verification email? My email client slapped a big warning on it:

⚠️ This email has failed its domain's authentication requirements. It may be spoofed or improperly forwarded.

The Pope's official prayer app is sending emails that look like phishing. Their SPF, DKIM, or DMARC is misconfigured, which means their legitimate emails are indistinguishable from someone impersonating them. So not only is the API leaking 700,000 email addresses that could be used for phishing, but the real emails from Click To Pray already look like phishing. An attacker wouldn't even need to try hard. They could send a pixel-perfect phishing email and it would have the same level of email authentication as the real thing: none. God works in mysterious ways.

Disclosure

I found this in early January 2026 and on January 3rd I emailed nine people: the general info address, six individual staff members at clicktopray.org, and two contacts at popesprayer.va (the Pope's Worldwide Prayer Network). No response. From any of them.

Six months. Nothing. No fix. No acknowledgment. The vulnerability stayed wide open while hundreds of thousands of users kept signing up to pray, handing over their email addresses to a platform that couldn't be bothered to protect them.

Eventually I brought it to a journalist at Dark Reading. They reached out to the Pope's Worldwide Prayer Network's press...

email user prayer click pray pope

Related Articles