That is not how I read it. You could argue the other way:
If they have to send password reset URL:s anyway, they can just as well send the password itself.
That makes sense. It's just that by storing the passwords at all, you risk losing them if someone gains access to your database.