Note that LastPass never holds decrypted keys or passwords on the server side... https://lastpass.com/support.php?cmd=showfaq&id=1116
Still, the fact that lastpass.com (and mail.yahoo.com by the way!) still has this vulnerability is extremely concerning.