I consider very significant just the fact that the plugin generates 19 (!!!) additional database tables.
Hi! my blog has been hacked 3 minutes after i have updated to WP3.5 (11/dec/2012) with the same method: systemwpadmin, ID88888, ecc.
My web host is Godaddy. The attacks came from a Godaddy IP: p3nlhg538.shr.prod.phx3.secureserver.net (IP 184.168.193.116).