Urgh, I hadn't thought of that. It would seem unlikely that anyone who did get onto the network would find their way to the dongle admin page, but certainly not impossible, and as you say, I can see that the password is displayed in plain text on there (GivEnergy really need to do some work on their security!)Regarding this more specifically, it's actually worse than you think, because if someone has connected to your WiFi dongle, yes they can browse the internet probably very poorly. Being connected to this though, if they get into the dongle admin portal with the insecure password it came with, they can read your current WiFi password and SSID in plain text within the STA Interface Setting page.
Seems like I've got a fun day ahead of changing wi-fi passwords on a variety of smart devices, each with their own different and usually long-winded and annoying way of updating their settings.