It's the lowest hanging fruit. I doubt he expected to find the password just sitting there, but since he did, here we are :)
But yes, keeping sensitive information hidden in plain text considered a security flaw.