We are also having this issue with some of our client sites.
This is what i’ve noticed:
Affects these versions: 2.9.2, 3.0, 3.1
Eeven sites that dont get indexed by google and no one is linking to are still getting hit.
One way we replicated these sites was to use the same wordpress files, if these files had been compromised could this explain why non-linked and non-indexable blogs were getting hit?
Here is a list of plugins that all our site sthat have been hit have:
Contact 7,
Hello Dolly,
Really Simple Captcha,
User Avatar,
WP Post Thumbnail,
Nextgen Gallery
Hopesomeone can help.
I’ll keep you updated on our progress as we try various fixes