← Click To Pray / Pope's Worldwide Prayer Network

2026 Click To Pray — IDOR exposed 719,517 accounts (names, emails; Jul reporting)

2026 719.5K records affected Share on X

Data compromised

Per researcher and independent verification (SAN.com Jul 24, 2026): names, email addresses, and countries for ~719,517 registered accounts; flaw reportedly still live at reporting time; Pope's Worldwide Prayer Network had not publicly responded

Technical writeup

Verified security exposure — researcher disclosure Jan 3, 2026; trade press Jul 24–25, 2026. Security researcher BobDaHacker reported an insecure direct object reference on the Click To Pray web API: after signup, incrementing a numeric user ID in a URL returned other users' names, emails, and countries. The researcher emailed nine Vatican/Prayer Network contacts on Jan 3, 2026 and received no response; as of July 2026 counted 719,517 registered accounts and said the flaw remained live. Straight Arrow News independently reproduced the issue. Dark Reading and DataBreaches.net covered the exposure. The Pope's Worldwide Prayer Network had not issued a public breach notice in sources reviewed. BreachHistory indexes 719,517 per the researcher's account count.

Root cause

Insecure direct object reference on clicktopray.org allowed sequential user-ID enumeration to retrieve other users' profile data; researcher BobDaHacker reported Jan 3, 2026 with no vendor response through Jul 2026 (SAN.com, Dark Reading)

References