That's what I'm guessing too. Magento and WordPress both store only the hashed passwords in the database; however, a screenshot from the article shows that the hosting company had stored plain-text passwords for an admin user, which were likely generated automatically, and stored in a separate (and publicly accessible) database.
My hosting provider (to remain nameless) also offers a global login bypass for WP and it gives me the willies.
There are a few hosting billing system -> account creation products that will generate the login information at purchase time so they can be presented to the user in plain text before being sent over to the provisioned server. It could be being logged accidentally at that point.
What would be a proper way to handle it?
They have access to the DB users. You can craft a new user & password-hash pair and insert it into the DB to create your own Wordpress user to manage on their behalf, or the lazy way is to just update the user’s password hash with your own. Then when you fix the issue, revert it. Worked for me years ago, not sure if something fundamental changed
Implement a proxy authentication scheme for the hosted services (WP, etc). Now an admin working for the hosting provider can log in using a password checked against a hash stored in their hosting system. No plaintext passwords stored.
> the hosting provider can log in using a password checked
Hmm, but where is this password stored? This sounds like exactly what they were doing!