I would argue that looking at the type of data you're dealing with is actually a very important part to assess the impact, but looking at the data itself is beyond this part.
Knowing that they store passwords in plaintext is a security issue on top of the R/W credential