fix xss attack if wgRawHtml is enabled