So basically on the WireGuard interface to public interface topology
Ideally there should be a single src NAT where every WG subnet is NATted for destination 0.0.0.0/0 with the public interface as the outgoing interface
I'm guessing that's have you done anyway