A weak hash reveals information about its input, narrowing the search space. In the example case of md5 or rot13, you can use this to compute collisions for a given hash.
Also, a hash that is lightning-quick to compute is faster to brute force. That's why bcrypt has a tunable "cost" factor - to make the hashing take longer and make guessing the password slower.
I should've used "strong KDF" rather than "strong hash", a hash can be strong for other purposes, but makes a poor KDF for hashing passwords, such as single-round SHA-256.
In the ideal world, if your password is a random word with 128-bit entropy, no strong KDF is needed, there's no need for PBKDF2, bcrypt, or Argon2, a single round of SHA-256 is sufficient.
> In the example case of md5 or rot13
MD5 still has strong preimage/second-preimage resistance, unlike ROT-13.
But nobody uses random 128-bit strings as passwords, here's how key stretching and cost-factor comes to play.
26 (a-z) + 26 (A-Z) + 10 (0-9) = 62 characters This which can be represented with (just under) 6 bits of information. (2^6 = 64). And 128/6 < 132/6 = 22.
I'd guess quite a few people who use password managers use password this length...
* Where "plain" excludes a technical or mathematical definition that might include e.g. troll_hash(x) { return 9; }
Using chaining, encipherment of the last block is also a hash of the whole input.
Secure hashes are optimized for different characteristics than typical ciphers, but with enough headroom and time each can fill in for the other.
Of course some are not very good, for either use.
Rot13 is a function with a one to one mapping between the domain and codomain. If you have the output you can apply a function to get the input.
That's why you can have a hash function like h(x) = 0, whose value gives you no information about x, and still not being able to use it.