Woody has just posted news, with title "Foxit security problem - disable it now".
(Link to Ask Woody is at the bottom of the Lounge page)
He describes the hole as very bad -- see his article.
As I type, he says 2.3.2912 is promised by Foxit a in the wings and hole-free,
but not available yet. He says present version is "build 2385", though I notice
that 2825 is what they offer. I don't know if it's Woody's error (I've sent him a comment)
or if they switched back to 2825 and it is hole-free. I'm assuming the former as that is