The phrasing was "both exploits do require tricking a user via a phishing attack into going to a malicious website".
This suggests that the blogger believes that the only attack vector involves tricking the user to go to a malicious website; I can reasonably see calling such attacks phishing attacks.
The problem (which is, in my opinion, more serious) is that, as you identify, the blogger seems to horribly misunderstand the potential attack vectors.
And there's nothing in their response that tries shifting the blame: https://blog.lastpass.com/2016/07/lastpass-security-updates....
This was not necessary for this attack to be successful on the default configuration of the tool. That's what I take issue with.
I feel like I'm reading some person's pet Wikipedia page. If they do then at least give some examples. You can't just say damning things and expect everyone to take it at face value.