If you visit a malicious site and click anywhere on the page (not on a plugin) then you could enable a click 2 play plugin. i raised this as a chrome bug and they said click 2 play is not a security feature. there may be even worse bypasses :(
the only way to have proper security is to disable the plugin. there is a button on the address bar that allows you to enable plugins on a page when they have been disabled. this gives you a similar experience to click2play but it is quite annoying especially if you are used to click2play.
I can't reply further down the comment thread, but can you provide an official source on this. I enabled this feature last week, and there's no way of interacting with the plugin until I click on it.