Overview
- A security researcher found in early January 2026 that the Click To Pray API returned other users’ data when callers iterated predictable numeric user IDs.
- The exposed fields included names, email addresses, country, birthdate, account role, and deletion status with no ownership checks or authentication.
- The API had no rate limits and revealed implementation details, making it trivial for an attacker to scrape hundreds of thousands of accounts quickly.
- Emails sent from the service failed domain authentication checks, which increased the risk that real messages would be treated as phishing or could be spoofed by attackers.
- The researcher reported the flaw to Vatican and Click To Pray contacts on January 3 and saw no substantive response for months before publicly disclosing it on July 24, after which the endpoint was quietly restricted and no formal statement has been released.