Check your sip trace and makes sure clients connected over wireguard are not offering SDP over IP address that is not routable over wireguard or not even allowed over allowed-ips of wireguard client config.
Faced the same when clients connect over wireguard vpn long time ago and they used to send their public ip in the sdp body while i had no stun/turn/ice configured anywhere for the media to pass over public internet properly.