Even a bug-free program might be exploitable.
:-P
The user may have no idea that the plugin is malicious; the program remains bug-free (if it was beforehand).
Much more agregiously you can design harmless a looking format that can run arbitrary code e.g. .doc with VBS. I have a very hard time blaming an user who falls for that even though MS puts up a scary looking popup.