Many sites do this, which is why when I'm on a public wireless setup (or other relatively untrusted network) nothing leaves my machine except through my OpenVPN setup.
Even if the login procedure were protected by HTTPS though, damage can still be done if the rest of the session reverts to plain HTTP, Someone sniffing the wireless (or the wire, for that matter) for usernames and passwords could equality sniff for session IDs and use them to mimic you in the web server's eye (so they can read your otherwise private data, posting as you, and so forth).
So if you are concerned that your login credentials are sent plain, you should be concerned that other data (session information specifically) is too.