I've noticed a lot of hits to the plugin directory for WPEasyStats. Did a google and found it's prone to a remote file inclusion exploit. the exact exploit is shown here:
http://www.exploit-db.com/exploits/17862/
Please can the developer release a fix.