Yes, its amazing how clearly you can articulate the facts, with so few words.
Simply port forwarding the incoming wg port to the lanip of the wireguard server
ON THE NETWORK.
Confusion stems as the OP stated he is running the wireguard
ON THE 5009
In any case you can port forward to any IP address, so the server can be on any VLAN one wishes.
With proper firewall rules, aka drop all else at end of forward chain, no one has access to the server and the server has access to nothing.
Just add the forward rules for allowed traffic and done.