Pope's official prayer app commits cardinal sin, leaks 700K+ users' info 40%

7/24/2026, 10:19:16 PM

BS Summary: This article contains 22 faulty reasoning types, including Anecdotal, Availability Heuristic, and Burden of Proof, with Negativity Bias as the most egregious example at 31.7% saturation with 208 hits. Analysis detected 1,005 faulty-reasoning hits from 657 analyzed words, generating a BS Score of 44.9% and a BS Rank of 40% (13,267 of 21,887 articles). This article is better (less manipulative) than 60.60% of the article peer group.

Click To Pray, a prayer app endorsed by the Pope with hundreds of thousands of users worldwide, has leaked people’s names and email addresses for months - or longer - according to an ethical hacker who said she found and reported the security vulnerability six months ago to no avail. 
This app needs to take a vow of silence when it comes to your personal information. 
The app, available in seven languages and on iOS, Android, and clicktopray.org, is the official app of the Pope's Worldwide Prayer Network. 
It connects users across the globe to pray for the Holy Father’s intentions, and as of July 2026, it has 719,517 registered accounts. 
It’s also very leaky, according to security sleuth BobDaHacker, who says she spotted and disclosed the vulnerability to the Pope’s Worldwide Prayer Network on January 3. 
“The vulnerability is still live,” the hacker said in a Friday blog. 
“Nobody has ever responded. 
I guess my email wasn't in their prayers." 
The Reg readers likely remember BobDaHacker for her previous research exposing a free-food flaw in McDonald's ordering system and open controls on Chinese robot manufacturer Pudu Robotics. 
This latest security hole stems from an Insecure Direct Object Reference (IDOR) bug in the prayer app. 
This is a very common and easy-to-exploit type of flaw that occurs when a website or an app blindly accepts user-provided input to view or modify resources without checking to see if the user is actually authorized to retrieve the data. 
“You ask for your own data, the server gives it to you,” BobDaHacker explains. 
“You ask for someone else's data, the server gives you that too. 
Thou shalt not authorize, apparently.” 
When you sign up for a Click To Pray account, the app assigns you a sequential numeric user ID. 
As BobDaHacker uncovered, the API endpoint GET https://api[.]clicktopray.org/user/users/{id} will return user data for any account - not just your own account - so long as you supply a valid, five-digit user ID. 
It doesn’t perform any authorization check or ownership validation. 
“Just increment the number and get someone else's data,” she wrote. 
This data includes users’ email addresses, first and last names, country, dates of birth, and whether the account has been deleted, and the API exposes all 719,517 accounts on the prayer site. 
“With sequential user IDs and no rate limiting, an attacker could enumerate every single account on the platform,” the hacker explained. 
“One GET request per user. for i in range(1, 719518): scrape(). 
That's it. 
That's the exploit.” 
As BobDaHacker points out, many of these users are likely older individuals, not all that tech savvy, and very trusting of anything Vatican related, making these exposed accounts a “phishing goldmine.” 
“Imagine getting an email that says ‘The Holy Father requests your urgent attention’ with a Vatican-looking link,” she wrote. 
“Grandma is clicking that. 
Every time.” 
And then it gets even worse. 
The signup endpoint, POST https://api.clicktopray.org/user/users/sign-up, returns the account's validation_hash directly in the response body, and that value is the same UUID used in the email verification link. 
This means someone could sign up using any email address and verify the account before the confirmation message reached the inbox. 
Plus, BobDaHacker’s email client flagged the real verification email with a warning that it had failed the domain’s authentication requirements and might have been spoofed or improperly forwarded. 
“So not only is the API leaking 700,000 email addresses that could be used for phishing, but the real emails from Click To Pray already look like phishing,” the hacker noted. 
“An attacker wouldn't even need to try hard. 
They could send a pixel-perfect phishing email and it would have the same level of email authentication as the real thing: none. 
God works in mysterious ways.” 
The Register reached out to the Pope's Worldwide Prayer Network and did not receive any response. 
BobDaHacker says she’s still praying for one, too. 
® 
Article reasoning-pattern comparisonThis article: 7.6%The Register: 3.3%Confirmation Bias7.6%This article: 0.0%The Register: 1.0%Anchoring Bias0.0%This article: 13.5%The Register: 3.2%Availability Heuristic13.5%This article: 0.0%The Register: 1.1%Representativeness Heuristic0.0%This article: 0.0%The Register: 1.3%Hindsight Bias0.0%This article: 4.6%The Register: 2.3%Overconfidence Bias4.6%This article: 1.7%The Register: 5.0%Framing Effect1.7%This article: 0.0%The Register: 0.7%Loss Aversion0.0%This article: 0.0%The Register: 0.8%Status Quo Bias0.0%This article: 0.0%The Register: 0.2%Sunk Cost Effect0.0%This article: 0.0%The Register: 3.0%Optimism Bias0.0%This article: 6.4%The Register: 2.6%Pessimism Bias6.4%This article: 31.7%The Register: 8.2%Negativity Bias31.7%This article: 1.2%The Register: 1.9%Self-Serving Bias1.2%This article: 0.0%The Register: 0.8%Fundamental Attribution Error0.0%This article: 0.0%The Register: 0.1%Actor-Observer Bias0.0%This article: 0.0%The Register: 0.4%In-Group Bias0.0%This article: 0.6%The Register: 0.4%Out-Group Homogeneity Bias0.6%This article: 4.1%The Register: 1.4%Halo Effect4.1%This article: 0.0%The Register: 0.1%Horn Effect0.0%This article: 0.0%The Register: 0.0%Dunning-Kruger Effect0.0%This article: 8.1%The Register: 1.9%Recency Bias8.1%This article: 2.6%The Register: 0.3%Primacy Effect2.6%This article: 0.0%The Register: 0.1%Blind-Spot Bias0.0%This article: 0.0%The Register: 0.7%Ad Hominem0.0%This article: 0.0%The Register: 0.2%Straw Man0.0%This article: 4.1%The Register: 4.2%Appeal to Authority4.1%This article: 0.0%The Register: 1.7%False Dilemma0.0%This article: 0.9%The Register: 1.2%Slippery Slope0.9%This article: 0.0%The Register: 0.1%Circular Reasoning0.0%This article: 10.2%The Register: 6.2%Hasty Generalization10.2%This article: 0.0%The Register: 0.3%Red Herring0.0%This article: 0.0%The Register: 0.7%Bandwagon0.0%This article: 8.4%The Register: 3.0%Appeal to Emotion8.4%This article: 0.0%The Register: 0.9%Begging the Question0.0%This article: 3.2%The Register: 2.0%Post Hoc (False Cause)3.2%This article: 0.0%The Register: 0.2%Tu Quoque0.0%This article: 10.7%The Register: 0.7%Burden of Proof10.7%This article: 0.0%The Register: 0.2%Appeal to Nature0.0%This article: 0.0%The Register: 0.3%Composition/Division0.0%This article: 17.0%The Register: 2.2%Anecdotal17.0%This article: 0.0%The Register: 0.0%No True Scotsman0.0%This article: 0.0%The Register: 2.1%Ambiguity (Equivocation)0.0%This article: 0.0%The Register: 0.0%Gambler’s Fallacy0.0%This article: 0.0%The Register: 0.1%Middle Ground0.0%This article: 0.0%The Register: 0.1%Personal Incredulity0.0%This article: 0.0%The Register: 0.2%Special Pleading0.0%This article: 0.0%The Register: 0.2%Genetic Fallacy0.0%This article: 7.6%The Register: 2.3%Unattributed Quote7.6%This article: 4.0%The Register: 1.3%Quote-first Misdirection4.0%This article: 1.7%The Register: 7.3%Biased Writer Voice1.7%This article: 3.2%The Register: 1.5%Indoctrination3.2%This article: 0.0%The Register: 0.2%Politically Left Leaning Bias0.0%This article: 0.0%The Register: 0.1%Politically Right Leaning Bias0.0%This article: 0.0%The Register: 2.5%Attempt to Sell a Product or S…0.0%

657 words analyzed.

Speakers

1speaker44%attributed speech371writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 11 words • 100.0% coverageWriter's voice • 50 words • 100.0% coverageWriter's voice • 16 words • 100.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageBobDaHacker • 26 words • 100.0% coverageBobDaHacker • 12 words • 0.0% coverageBobDaHacker • 4 words • 0.0% coverageBobDaHacker • 8 words • 0.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 41 words • 0.0% coverageBobDaHacker • 14 words • 0.0% coverageBobDaHacker • 12 words • 0.0% coverageBobDaHacker • 5 words • 100.0% coverageWriter's voice • 19 words • 0.0% coverageBobDaHacker • 32 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageBobDaHacker • 11 words • 0.0% coverageWriter's voice • 32 words • 0.0% coverageBobDaHacker • 21 words • 0.0% coverageBobDaHacker • 11 words • 0.0% coverageWriter's voice • 2 words • 0.0% coverageWriter's voice • 3 words • 0.0% coverageBobDaHacker • 31 words • 0.0% coverageBobDaHacker • 19 words • 0.0% coverageBobDaHacker • 4 words • 0.0% coverageBobDaHacker • 2 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageBobDaHacker • 31 words • 0.0% coverageBobDaHacker • 8 words • 0.0% coverageBobDaHacker • 22 words • 0.0% coverageBobDaHacker • 5 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageBobDaHacker • 8 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverage
Selected voice

BobDaHacker

76%flagged-word coverage
286 attributed words100% of attributed speech67% writer coverage
0%7.5%15.0%Unattributed Quote-13.5 ptsWriter: 13.5%BobDaHacker: 0.0%0.0%Quote-first Misdirection+9.1 ptsWriter: 0.0%BobDaHacker: 9.1%9.1%Indoctrination-2.6 ptsWriter: 4.3%BobDaHacker: 1.7%1.7%Biased Writer Voice-3.0 ptsWriter: 3.0%BobDaHacker: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.