They dont need to store your pasword in plaintext for this, but it does raise a security concern. 3 times the chances to have your password guessed by brute force!
I think it would be worrisome if there weren't protective measures already in place, such as limited login attempts, two-factor auth, and so on.
The other weakness would be the repetition of that password on sites that place a low priority on, or are ignorant about, security. At which point, it doesn't even matter.
I was confused until I realized the caps lock case only applies to Windows users.