The vulnerability shouldn't be too much of an issue if the electrum wallet is encrypted. Unless it gets decrypted while the user if on another page/has an established connection with a server untrustworthy.
Unless the payto field gets edited also via jsonrpc calls.
@op, I'd suggest a full virus scan on your computer before putting the new software on in case it's a virus. There's free software like malware bytes and free trials of other services like McAfee.