Im very sorry, you are right. I dont have to directly accuse the plugin as a virus but it maybe have one or any vulnerability. This is a single entry on my security log:
[unique_id “XXXXXXXXXXXXXXXXXxx”]
[Sat Jan 29 19:24:50 2011] [error] [client XXXXXXXXX]
ModSecurity: Access denied with code 406 (phase 2). Pattern match
“\\b(\\d+) ?= ?\\1\\b|[\\'”](\\w+)[\\'”] ?= ?[\\'”]\\2\\b” at
REQUEST_HEADERS:Cookie. [file
“XXXXXXXXXXXXXX”] [line “86”] [id “XXXXX”]
[msg “SQL Injection Attack”] [data “1=1”] [severity “CRITICAL”] [tag
“WEB_ATTACK/SQL_INJECTION”] [hostname “XXXXXXXXXXXX”] [uri
“/wp-content/plugins/tabbed-widgets/css/tabbed-widgets.css”]
It happens with this file aswell: /wp-content/plugins/tabbed-widgets/js/jquery-cookie.min.js
I dont know if that helps.