As far as I know this has nothing to do with plugins...
This happened to two of my forums. I upgraded to the latest version and it just happened again... I host with Rackspace which went over my machine looking for vulnerabilties the first time this happened...
I think it is a whole in vbulletin.
Is there a way to
lock the
spacer_open table in the database to stop them from inserting their code?
--------------- Added [DATE]1223661876[/DATE] at [TIME]1223661876[/TIME] ---------------
this is a pretty decent size vulnerability... happened to me again...