Can some vulnerabilities in plugins be exploited even when the plugin is inactive?

I just received a notification from the developers of the Wordfence security plugin of several vulnerabilities that exist in other popular Wordpress plugins. One example in this case is a mailchimp form plugin which is likely to be quite widely used.

I'm interested to know whether some plugin vulnerabilities can be exploited even if the plugin is inactive? (ie the plugin is present on a site, but currently not activated)


