I was just thinking about this: when I change my router and I use the same SSID and password, all my devices automatically connect. So that implies the devices are sending the old password to the new router.
What exactly stops someone from setting up a router, naming it the same SSID, and collecting the passwords that the devices are trying to authenticate with?