We should reframe the discussion around that, because it is the real issue.
But let's pretend that PoF stores a 128-iteration blowfish ciphered password for every user. The site is compromised, as it was, and the attacker now has the run of the place. They inject their capture into the login process and now they siphon off every plaintext password.
On the scale of things, whether the password is stored hashed or not is very, very low. It masks the real problem.