Of course the password is in plaintext. Logins are done via HTTP, not via HTTPS. You know, there isn't that little yellow lock thingy in the bottom left corner of the window? Is this really news to anyone?
I'm surprised that the crowd here would even blink when hearing this. cperciva is right with his rhetorical question: this shouldn't be news to anyone, especially hackers.