Unless/until Tesco have their databases hacked or stolen there is no risk at all.
This is not the case. The most glaring reason why was pointed out in the posted article. It very clearly showed that Tesco failed to communicate logged-in state information (stored in a cookie) between the client and server over an encrypted line. This means your account is vulnerable to attack without the entire db being leaked.
Poor security references far more than just poor password storage, but even poor password security by itself becomes a serious issue incredibly quickly. Most people re-use passwords and most passwords are reset by email, meaning a leaked password and email address combo can quickly lead to massive damage.
Not all security exploits require a database to be hacked either. Even if a database is hacked, half the time we're finding out about this from third party sources well after the fact instead of the companies released press releases themselves.
These things happening silently is horrific[1]. Malware or phishing sites are relatively easy to spot and defend against -- but what about a compromised but legitimate website? If I find a security hole and pick a small but high quality selection of targets, how long will it take authorities (if ever) to piece together that they all were members of CornerStore Online?
A conditional statement saying there is no risk is utter nonsense. The reason for this is very simple - there is always a risk the conditional has already been fulfilled.
Yes, a phishing site needs to trick me, and a malware site needs to get through my browser sandbox, and any anti-virus software I might have installed.
I site with poor security (and a large user base) can be assumed to give my information to the first script kiddie that asks for it.
Really? This password storage isn't great, but using tesco.com is hardly the same as visiting a malware or phishing site.
Unless/until Tesco have their databases hacked or stolen there is no risk at all.