If this is true:
If you report the message it then the full text gets sent to WhatsApp.
That means there's a software switch that dumps a plaintext copy of a supposedly encrypted message when flipped.
Therefore, all you need to read any WhatsApp message is the ability to flag the message as "reported", and access to wherever the plaintext copies get sent.
Considering how often security is an afterthought for corporations, the access part is probably easy.