I edited the article because I really missed this point, you are right. I thought WhatsApp is not sending the message which got encrypted with the new key.
But still, I would not say this is a backdoor, because the user has a relatively easy way to check the keys. If WhatsApp would like to implement a backdoor, they would have done it in a different way I think.
As I said in the Post, it is not a security vulnerability itself, but I want to point out that it can be very dangerous to put a password in a GET request.
And the response of ebay is bad too.
But thank you for your constructive comment ;)