Passwords in plaintext can be directly accessed by attackers.
When passwords are stored as plaintext, anyone who gains access to the database can see them directly. This can lead to unauthorized access to user accounts. For example, if an e-commerce site is breached and passwords are stored in plaintext, attackers can log into user accounts and possibly reuse passwords on other sites.