Of course. If you send a password (or anything else) via email without encryption, it is trivial for an unauthorized party to intercept the email and extract the password. You could use PGP to fix that problem, but then your users must use PGP and register their keys with your website.
Sincerely,
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.