• Sources: researcher writeup, Dark Reading, The Register
  • Summary: A researcher publishing as BobDaHacker disclosed on 2026-07-24 an insecure direct object reference in the API behind Click to Pray, the official app of the Pope's Worldwide Prayer Network. A single unauthenticated endpoint returned a user record for any numeric id, so incrementing the id enumerated roughly 719,517 accounts and returned email address, first and last name, country, date of birth, account role, and deletion state in plaintext. The researcher reports contacting nine addresses at the operator and its developer on 2026-01-03 with no reply over six months, and states the endpoint was narrowed to return only the requesting user's own email after Dark Reading published the finding. Dark Reading and The Register independently confirmed the exposure.
  • Why it matters: Nothing here needed a tool beyond a browser, and the failure is the one every REST resource with a sequential primary key invites when authorization is checked at the route and not at the record.
  • Follow-up: Watch for a statement from the Pope's Worldwide Prayer Network or the app developer, and for confirmation of how long the endpoint was open.

send feedback on this story