WG itself doesn't support user authentication of any kind, it's just a tunnel. If you have the right key and send a properly signed packet WG will pass it. Encryption keys are not authentication in of themselves.
How would an adversary do this without the private key?
Wireguard uses ChaCha20Poly1305, an AEAD scheme. The first A stands for Authenticated.
Authentication just means proving who or what you are. Secret keys, whether they be passwords or encryption keys, are one of the primary ways to do this. Just because the key is also used for something else in addition to, or as part of, that process doesn't change it from being authentication.