I found out this the hard way. With version 2.03 of Advanced Poll the attackers used external scripts to send spam. Only when the web host disabled the website due to spam complaints did we find out.
I hope this has been fixed in newer versions (I couldn't find a change log to check) before it happens to someone else.