It is worse than plain HTTP, actually. Heartblead allows an attacker anywhere on the internet to read out memory from your server. This is worse than plain HTTP in two ways:
- With plain HTTP, the attacker would have to be in a MITM position to intercept traffic. With Heartblead, he can read traffic he wouldn't normally have access to from the server's memory.
- There may be secrets in memory that would never even be sent over the network that are now accessible. For example, if running a web app in the same process doing SSL termination, private keys such as Django's SECRET_KEY may be available. Under certain situations, knowledge of the SECRET_KEY can effect remote code execution.
In short, Heartbleed gives the entire world the ability to read memory from your server. This is much worse than an HTTP MITM.