1. Mallory enters Alice's username and a random password
2. Website sends back Alice's plaintext password to be checked client side
3. Mallory inspects network traffic and retrieves Alice's plaintext password
It's also bad if the hash is sent back; now Mallory can run all sorts of attacks on the hash itself without worrying about rate limits or any other protection the site operator could implement.