If they used the same password on the forums and blog then they still have a problem. They need to be notified of this and change the password to a more secure one.
The config.php file should not be readable by an anonymous user, that is a security risk.