The official papal prayer application Click To Pray has leaked personal data belonging to 719,000 users due to an IDOR (Insecure Direct Object Reference) vulnerability. The flaw allows attackers to access any user account by using a valid ID number without proper authorization checks.
Exposed information includes names, surnames, email addresses, countries, and dates of birth. The vulnerability was reported on January 3, but Pope's Worldwide Prayer Network, the organization responsible for the app, has not yet responded to the disclosure.
According to security researchers who discovered the issue, the weakness stems from insufficient authorization validation in the application's backend systems. Users of the app are at risk until the organization patches the vulnerability and implements proper access controls to verify user permissions before granting access to account data.

