Nulled plugins are the most common delivery method for malware. Hackers often inject malicious code into the plugin files, creating "backdoors" that allow them to take control of your site, steal user data, or use your server to send spam emails.
Vulnerabilities are discovered in plugins constantly. Legit users receive automatic patches to fix these holes. If you use a nulled version, you won't receive these updates, leaving your site permanently exposed to known exploits.