This is absolutely atrocious if this is the case. MD5, even with a salt, can be cracked in a matter of seconds even with the most basic hardware. MD5 hasn't been an acceptable password hashing algorithm for at least a decade now, and StockX was created in 2015, long after the creators should have known better (sadly, despite this, an absurdly high number of companies still use MD5 for pass hashing).
These passwords, hashed with MD5, might as well be considered to have been stored in plaintext.