Already, two of my Facebook friends have reported they have been hit with this vulnerability.
Beside, this XSS vulnerability is silent by nature. The victim has no idea and no visual indication that clicking a link ends up stealing his/her Yahoo auth cookies.
So I think this is more than spoofed email. Plus, having both of these friends, with Yahoo accounts, report this on the same day of this vulnerability going public is a pretty big coincidence.